{"api_version":"1","generated_at":"2026-07-24T02:23:20+00:00","cve":"CVE-2016-1632","urls":{"html":"https://cve.report/CVE-2016-1632","api":"https://cve.report/api/cve/CVE-2016-1632.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-1632","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-1632"},"summary":{"title":"CVE-2016-1632","description":"The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own properties, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code that triggers an incorrect cast, related to extensions/renderer/v8_helpers.h and gin/converter.h.","state":"PUBLISHED","assigner":"Chrome","published_at":"2016-03-06 02:59:03","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"8.8","severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00028.html","name":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00028.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] openSUSE-SU-2016:0729-1: important: Security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1035185","name":"http://www.securitytracker.com/id/1035185","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Google Chrome Multiple Bugs Let Remote Users Execute Arbitrary Code, Bypass Security Restrictions, and Obtain Potentially Sensitive Information - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://codereview.chromium.org/1433293004","name":"https://codereview.chromium.org/1433293004","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Issue 1433293004: [Extensions] Don't allow gin::Define to be overridden -\n    \n    Code Review","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00014.html","name":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00014.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] openSUSE-SU-2016:0664-1: important: Security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://code.google.com/p/chromium/issues/detail?id=549986","name":"https://code.google.com/p/chromium/issues/detail?id=549986","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"549986 - \n \n \n chromium -\n \n \n An open-source project to help move the web forward. - \n \n Monorail","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.securityfocus.com/bid/84008","name":"http://www.securityfocus.com/bid/84008","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Google Chrome Prior to 49.0.2623.75 Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00018.html","name":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00018.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] openSUSE-SU-2016:0684-1: important: Security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00015.html","name":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00015.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] SUSE-SU-2016:0665-1: important: Security update for","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2016/dsa-3507","name":"http://www.debian.org/security/2016/dsa-3507","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-3507-1 chromium-browser","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/201603-09","name":"https://security.gentoo.org/glsa/201603-09","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Chromium: Multiple vulnerabilities (GLSA 201603-09) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html","name":"http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Chrome Releases: Stable Channel Update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-1632","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-1632","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"1632","vulnerable":"1","versionEndIncluding":"48.0.2564.116","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"google","cpe5":"chrome","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T23:02:12.407Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"openSUSE-SU-2016:0664","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00014.html"},{"name":"openSUSE-SU-2016:0684","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00018.html"},{"name":"84008","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/84008"},{"name":"DSA-3507","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2016/dsa-3507"},{"name":"1035185","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1035185"},{"name":"openSUSE-SU-2016:0729","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00028.html"},{"name":"SUSE-SU-2016:0665","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00015.html"},{"name":"GLSA-201603-09","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"https://security.gentoo.org/glsa/201603-09"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://codereview.chromium.org/1433293004"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://code.google.com/p/chromium/issues/detail?id=549986"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2016-03-02T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own properties, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code that triggers an incorrect cast, related to extensions/renderer/v8_helpers.h and gin/converter.h."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-12-01T15:57:02.000Z","orgId":"ebfee0ef-53dd-4cf3-9e2a-08a5bd7a7e28","shortName":"Chrome"},"references":[{"name":"openSUSE-SU-2016:0664","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00014.html"},{"name":"openSUSE-SU-2016:0684","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00018.html"},{"name":"84008","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/84008"},{"name":"DSA-3507","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2016/dsa-3507"},{"name":"1035185","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1035185"},{"name":"openSUSE-SU-2016:0729","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00028.html"},{"name":"SUSE-SU-2016:0665","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00015.html"},{"name":"GLSA-201603-09","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"https://security.gentoo.org/glsa/201603-09"},{"tags":["x_refsource_CONFIRM"],"url":"https://codereview.chromium.org/1433293004"},{"tags":["x_refsource_CONFIRM"],"url":"https://code.google.com/p/chromium/issues/detail?id=549986"},{"tags":["x_refsource_CONFIRM"],"url":"http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security@google.com","ID":"CVE-2016-1632","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own properties, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code that triggers an incorrect cast, related to extensions/renderer/v8_helpers.h and gin/converter.h."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"openSUSE-SU-2016:0664","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00014.html"},{"name":"openSUSE-SU-2016:0684","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00018.html"},{"name":"84008","refsource":"BID","url":"http://www.securityfocus.com/bid/84008"},{"name":"DSA-3507","refsource":"DEBIAN","url":"http://www.debian.org/security/2016/dsa-3507"},{"name":"1035185","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1035185"},{"name":"openSUSE-SU-2016:0729","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00028.html"},{"name":"SUSE-SU-2016:0665","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00015.html"},{"name":"GLSA-201603-09","refsource":"GENTOO","url":"https://security.gentoo.org/glsa/201603-09"},{"name":"https://codereview.chromium.org/1433293004","refsource":"CONFIRM","url":"https://codereview.chromium.org/1433293004"},{"name":"https://code.google.com/p/chromium/issues/detail?id=549986","refsource":"CONFIRM","url":"https://code.google.com/p/chromium/issues/detail?id=549986"},{"name":"http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html","refsource":"CONFIRM","url":"http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html"}]}}}},"cveMetadata":{"assignerOrgId":"ebfee0ef-53dd-4cf3-9e2a-08a5bd7a7e28","assignerShortName":"Chrome","cveId":"CVE-2016-1632","datePublished":"2016-03-06T02:00:00.000Z","dateReserved":"2016-01-12T00:00:00.000Z","dateUpdated":"2024-08-05T23:02:12.407Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2016-03-06 02:59:03","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","versionEndIncluding":"48.0.2564.116","matchCriteriaId":"99CABF0F-D201-46AE-83DC-09257264BF7D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"1632","Ordinal":"1","Title":"CVE-2016-1632","CVE":"CVE-2016-1632","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"1632","Ordinal":"1","NoteData":"The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own properties, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code that triggers an incorrect cast, related to extensions/renderer/v8_helpers.h and gin/converter.h.","Type":"Description","Title":"CVE-2016-1632"},{"CveYear":"2016","CveId":"1632","Ordinal":"2","NoteData":"2016-03-05","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"1632","Ordinal":"3","NoteData":"2016-12-01","Type":"Other","Title":"Modified"}]}}}