CVE-2016-1646

Confirmed PUBLISHED

The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider...

Google · Chrome
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.8 High

At a Glance

The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code.

cisa java
CVE Published
Mar 29, 2016
Exploitation Reported
Jun 08, 2022
CVSS
8.8 High
EPSS
Remote Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • RHSA-2016:0525 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2016-0525.html
  • openSUSE-SU-2016:0929 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00000...
  • openSUSE-SU-2016:1059 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00039...
  • DSA-3531 debian.org · Vendor Advisory http://www.debian.org/security/2016/dsa-3531
  • openSUSE-SU-2016:0930 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00001...
Show 6 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.