CVE-2016-1630: Google Chrome

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

The ContainerNode::parserRemoveChild function in WebKit/Source/core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 49.0.2623.75, mishandles widget updates, which makes it easier for remote attackers to bypass the Same Origin Policy via a crafted web site.

Affected products

  • Google Chrome: up to and including 48.0.2564.116

Published 2016-03-06. Last modified 2026-06-17.