Skip to content
COOEY

EXPOSURES › CVE-2016-1646

CVE-2016-1646

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-06-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-1646 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

A Chromium V8 out-of-bounds read vulnerability was actively exploited, impacting browsers like Chrome and Edge, potentially causing denial of service or other impacts.

This CVE represents a significant risk for DIB organizations relying on Chromium-based browsers, as it was actively exploited and could lead to system instability or data compromise. Failure to promptly patch exposes systems to potential attack vectors and negatively impacts NIST 800-171 compliance controls. Ensure all Chromium-based browsers are updated to the latest version.

Shame score — The vulnerability's active exploitation demonstrates a failure to maintain adequate security hygiene, despite the availability of mitigations.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium V8 Engine contains an out-of-bounds read vulnerability that allows a remote attacker to cause a denial of service or possibly have another unspecified impact via crafted JavaScript code. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized