CVE-2016-1632: Google Chrome

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own properties, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code that triggers an incorrect cast, related to extensions/renderer/v8_helpers.h and gin/converter.h.

Affected products

  • Google Chrome: up to and including 48.0.2564.116

Published 2016-03-06. Last modified 2026-06-17.