EXPOSURES › CVE-2016-1646
CVE-2016-1646
HIGH ⌖ ON CISA KEV · EXPLOITEDA Chromium V8 out-of-bounds read vulnerability was actively exploited, impacting browsers like Chrome and Edge, potentially causing denial of service or other impacts.
This CVE represents a significant risk for DIB organizations relying on Chromium-based browsers, as it was actively exploited and could lead to system instability or data compromise. Failure to promptly patch exposes systems to potential attack vectors and negatively impacts NIST 800-171 compliance controls. Ensure all Chromium-based browsers are updated to the latest version.
Shame score — The vulnerability's active exploitation demonstrates a failure to maintain adequate security hygiene, despite the availability of mitigations.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 Engine contains an out-of-bounds read vulnerability that allows a remote attacker to cause a denial of service or possibly have another unspecified impact via crafted JavaScript code. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
| PRODUCT | STATUS |
|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) Google |
Authorized |
| Google Workspace Google |
Authorized |