{"api_version":"1","generated_at":"2026-07-23T19:39:58+00:00","cve":"CVE-2016-1622","urls":{"html":"https://cve.report/CVE-2016-1622","api":"https://cve.report/api/cve/CVE-2016-1622.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-1622","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-1622"},"summary":{"title":"CVE-2016-1622","description":"The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extension behavior, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.","state":"PUBLISHED","assigner":"Chrome","published_at":"2016-02-14 02:59:00","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"8.8","severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://lists.opensuse.org/opensuse-updates/2016-02/msg00104.html","name":"http://lists.opensuse.org/opensuse-updates/2016-02/msg00104.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"openSUSE-SU-2016:0491-1: moderate: Security update for Chromium","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-updates/2016-02/msg00119.html","name":"http://lists.opensuse.org/opensuse-updates/2016-02/msg00119.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"openSUSE-SU-2016:0518-1: moderate: Security update for Chromium","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2016-0241.html","name":"http://rhn.redhat.com/errata/RHSA-2016-0241.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://googlechromereleases.blogspot.com/2016/02/stable-channel-update_9.html","name":"http://googlechromereleases.blogspot.com/2016/02/stable-channel-update_9.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Chrome Releases: Stable Channel Update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://code.google.com/p/chromium/issues/detail?id=546677","name":"https://code.google.com/p/chromium/issues/detail?id=546677","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"546677 - \n \n \n chromium -\n \n \n An open-source project to help move the web forward. - \n \n Monorail","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.debian.org/security/2016/dsa-3486","name":"http://www.debian.org/security/2016/dsa-3486","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-3486-1 chromium-browser","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/83125","name":"http://www.securityfocus.com/bid/83125","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Google Chrome Prior to 48.0.2564.109 Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://security.gentoo.org/glsa/201603-09","name":"https://security.gentoo.org/glsa/201603-09","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Chromium: Multiple vulnerabilities (GLSA 201603-09) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://codereview.chromium.org/1417513003","name":"https://codereview.chromium.org/1417513003","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Issue 1417513003: [Extensions] Don't allow built-in extensions code to be overridden -\n    \n    Code Review","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1035183","name":"http://www.securitytracker.com/id/1035183","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Google Chrome Bugs Let Remote Users Execute Arbitrary Code and Bypass Security Restrictions - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-1622","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-1622","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"1622","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"1622","vulnerable":"1","versionEndIncluding":"48.0.2564.103","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"google","cpe5":"chrome","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"1622","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"opensuse","cpe5":"opensuse","cpe6":"13.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T23:02:12.345Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"83125","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/83125"},{"name":"1035183","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1035183"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://code.google.com/p/chromium/issues/detail?id=546677"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://googlechromereleases.blogspot.com/2016/02/stable-channel-update_9.html"},{"name":"GLSA-201603-09","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"https://security.gentoo.org/glsa/201603-09"},{"name":"openSUSE-SU-2016:0491","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-updates/2016-02/msg00104.html"},{"name":"openSUSE-SU-2016:0518","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-updates/2016-02/msg00119.html"},{"name":"DSA-3486","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2016/dsa-3486"},{"name":"RHSA-2016:0241","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2016-0241.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://codereview.chromium.org/1417513003"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2016-02-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extension behavior, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-12-02T20:57:01.000Z","orgId":"ebfee0ef-53dd-4cf3-9e2a-08a5bd7a7e28","shortName":"Chrome"},"references":[{"name":"83125","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/83125"},{"name":"1035183","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1035183"},{"tags":["x_refsource_CONFIRM"],"url":"https://code.google.com/p/chromium/issues/detail?id=546677"},{"tags":["x_refsource_CONFIRM"],"url":"http://googlechromereleases.blogspot.com/2016/02/stable-channel-update_9.html"},{"name":"GLSA-201603-09","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"https://security.gentoo.org/glsa/201603-09"},{"name":"openSUSE-SU-2016:0491","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-updates/2016-02/msg00104.html"},{"name":"openSUSE-SU-2016:0518","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-updates/2016-02/msg00119.html"},{"name":"DSA-3486","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2016/dsa-3486"},{"name":"RHSA-2016:0241","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2016-0241.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://codereview.chromium.org/1417513003"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security@google.com","ID":"CVE-2016-1622","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extension behavior, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"83125","refsource":"BID","url":"http://www.securityfocus.com/bid/83125"},{"name":"1035183","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1035183"},{"name":"https://code.google.com/p/chromium/issues/detail?id=546677","refsource":"CONFIRM","url":"https://code.google.com/p/chromium/issues/detail?id=546677"},{"name":"http://googlechromereleases.blogspot.com/2016/02/stable-channel-update_9.html","refsource":"CONFIRM","url":"http://googlechromereleases.blogspot.com/2016/02/stable-channel-update_9.html"},{"name":"GLSA-201603-09","refsource":"GENTOO","url":"https://security.gentoo.org/glsa/201603-09"},{"name":"openSUSE-SU-2016:0491","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-updates/2016-02/msg00104.html"},{"name":"openSUSE-SU-2016:0518","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-updates/2016-02/msg00119.html"},{"name":"DSA-3486","refsource":"DEBIAN","url":"http://www.debian.org/security/2016/dsa-3486"},{"name":"RHSA-2016:0241","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2016-0241.html"},{"name":"https://codereview.chromium.org/1417513003","refsource":"CONFIRM","url":"https://codereview.chromium.org/1417513003"}]}}}},"cveMetadata":{"assignerOrgId":"ebfee0ef-53dd-4cf3-9e2a-08a5bd7a7e28","assignerShortName":"Chrome","cveId":"CVE-2016-1622","datePublished":"2016-02-14T02:00:00.000Z","dateReserved":"2016-01-12T00:00:00.000Z","dateUpdated":"2024-08-05T23:02:12.345Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2016-02-14 02:59:00","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","versionEndIncluding":"48.0.2564.103","matchCriteriaId":"4D0431D7-1966-45F0-8154-2C7B99E7D2CF"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","matchCriteriaId":"C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*","matchCriteriaId":"A10BC294-9196-425F-9FB0-B1625465B47F"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"1622","Ordinal":"1","Title":"CVE-2016-1622","CVE":"CVE-2016-1622","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"1622","Ordinal":"1","NoteData":"The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extension behavior, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.","Type":"Description","Title":"CVE-2016-1622"},{"CveYear":"2016","CveId":"1622","Ordinal":"2","NoteData":"2016-02-13","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"1622","Ordinal":"3","NoteData":"2016-12-02","Type":"Other","Title":"Modified"}]}}}