{"api_version":"1","generated_at":"2026-07-23T20:47:29+00:00","cve":"CVE-2016-1617","urls":{"html":"https://cve.report/CVE-2016-1617","api":"https://cve.report/api/cve/CVE-2016-1617.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-1617","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-1617"},"summary":{"title":"CVE-2016-1617","description":"The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply ws policies to wss URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report.","state":"PUBLISHED","assigner":"Chrome","published_at":"2016-01-25 11:59:05","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://codereview.chromium.org/1455973003","name":"https://codereview.chromium.org/1455973003","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Issue 1455973003: CSP: Source expressions can no longer lock sites into insecurity. -\n    \n    Code Review","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00035.html","name":"http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00035.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] openSUSE-SU-2016:0249-1: important: Security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://code.google.com/p/chromium/issues/detail?id=544765","name":"https://code.google.com/p/chromium/issues/detail?id=544765","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.securityfocus.com/bid/81430","name":"http://www.securityfocus.com/bid/81430","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Google Chrome Prior to 48.0.2564.82 Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.debian.org/security/2016/dsa-3456","name":"http://www.debian.org/security/2016/dsa-3456","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-3456-1 chromium-browser","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://googlechromereleases.blogspot.com/2016/01/stable-channel-update_20.html","name":"http://googlechromereleases.blogspot.com/2016/01/stable-channel-update_20.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Chrome Releases: Stable Channel Update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00036.html","name":"http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00036.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] openSUSE-SU-2016:0250-1: important: Security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00046.html","name":"http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00046.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] openSUSE-SU-2016:0271-1: important: Security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2016-0072.html","name":"http://rhn.redhat.com/errata/RHSA-2016-0072.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1034801","name":"http://www.securitytracker.com/id/1034801","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Google Chrome Multiple Bugs Let Remote Users Obtain Information, Bypass Security Restrictions, Spoof URLs, and Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/201603-09","name":"https://security.gentoo.org/glsa/201603-09","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Chromium: Multiple vulnerabilities (GLSA 201603-09) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/USN-2877-1","name":"http://www.ubuntu.com/usn/USN-2877-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"USN-2877-1: Oxide vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-1617","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-1617","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"1617","vulnerable":"1","versionEndIncluding":"47.0.2526.106","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"google","cpe5":"chrome","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T23:02:12.051Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"81430","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/81430"},{"name":"RHSA-2016:0072","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2016-0072.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://codereview.chromium.org/1455973003"},{"name":"USN-2877-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-2877-1"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://googlechromereleases.blogspot.com/2016/01/stable-channel-update_20.html"},{"name":"1034801","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1034801"},{"name":"openSUSE-SU-2016:0249","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00035.html"},{"name":"GLSA-201603-09","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"https://security.gentoo.org/glsa/201603-09"},{"name":"openSUSE-SU-2016:0271","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00046.html"},{"name":"DSA-3456","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2016/dsa-3456"},{"name":"openSUSE-SU-2016:0250","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00036.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://code.google.com/p/chromium/issues/detail?id=544765"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2016-01-20T00:00:00.000Z","descriptions":[{"lang":"en","value":"The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply ws policies to wss URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-12-05T14:57:01.000Z","orgId":"ebfee0ef-53dd-4cf3-9e2a-08a5bd7a7e28","shortName":"Chrome"},"references":[{"name":"81430","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/81430"},{"name":"RHSA-2016:0072","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2016-0072.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://codereview.chromium.org/1455973003"},{"name":"USN-2877-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-2877-1"},{"tags":["x_refsource_CONFIRM"],"url":"http://googlechromereleases.blogspot.com/2016/01/stable-channel-update_20.html"},{"name":"1034801","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1034801"},{"name":"openSUSE-SU-2016:0249","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00035.html"},{"name":"GLSA-201603-09","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"https://security.gentoo.org/glsa/201603-09"},{"name":"openSUSE-SU-2016:0271","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00046.html"},{"name":"DSA-3456","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2016/dsa-3456"},{"name":"openSUSE-SU-2016:0250","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00036.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://code.google.com/p/chromium/issues/detail?id=544765"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security@google.com","ID":"CVE-2016-1617","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply ws policies to wss URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"81430","refsource":"BID","url":"http://www.securityfocus.com/bid/81430"},{"name":"RHSA-2016:0072","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2016-0072.html"},{"name":"https://codereview.chromium.org/1455973003","refsource":"CONFIRM","url":"https://codereview.chromium.org/1455973003"},{"name":"USN-2877-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-2877-1"},{"name":"http://googlechromereleases.blogspot.com/2016/01/stable-channel-update_20.html","refsource":"CONFIRM","url":"http://googlechromereleases.blogspot.com/2016/01/stable-channel-update_20.html"},{"name":"1034801","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1034801"},{"name":"openSUSE-SU-2016:0249","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00035.html"},{"name":"GLSA-201603-09","refsource":"GENTOO","url":"https://security.gentoo.org/glsa/201603-09"},{"name":"openSUSE-SU-2016:0271","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00046.html"},{"name":"DSA-3456","refsource":"DEBIAN","url":"http://www.debian.org/security/2016/dsa-3456"},{"name":"openSUSE-SU-2016:0250","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00036.html"},{"name":"https://code.google.com/p/chromium/issues/detail?id=544765","refsource":"CONFIRM","url":"https://code.google.com/p/chromium/issues/detail?id=544765"}]}}}},"cveMetadata":{"assignerOrgId":"ebfee0ef-53dd-4cf3-9e2a-08a5bd7a7e28","assignerShortName":"Chrome","cveId":"CVE-2016-1617","datePublished":"2016-01-25T11:00:00.000Z","dateReserved":"2016-01-12T00:00:00.000Z","dateUpdated":"2024-08-05T23:02:12.051Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2016-01-25 11:59:05","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","versionEndIncluding":"47.0.2526.106","matchCriteriaId":"68EEC241-F8D3-4CF6-AE28-1B7BA2E4E6A4"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"1617","Ordinal":"1","Title":"CVE-2016-1617","CVE":"CVE-2016-1617","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"1617","Ordinal":"1","NoteData":"The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply ws policies to wss URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report.","Type":"Description","Title":"CVE-2016-1617"},{"CveYear":"2016","CveId":"1617","Ordinal":"2","NoteData":"2016-01-25","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"1617","Ordinal":"3","NoteData":"2016-12-05","Type":"Other","Title":"Modified"}]}}}