CVE-2016-1632: Google Chrome
High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.
The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own properties, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code that triggers an incorrect cast, related to extensions/renderer/v8_helpers.h and gin/converter.h.
Affected products
- Google Chrome: up to and including 48.0.2564.116
Published 2016-03-06. Last modified 2026-06-17.