CVE-2016-1646: Google Chromium V8 Out-of-Bounds Read Vulnerability
High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2022-06-08. EPSS: 48.1% chance of exploitation in the next 30 days.
The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 15.10 only; version 16.04 only
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Google Chrome: before 49.0.2623.108 (fixed in 49.0.2623.108)
- Opensuse Leap: version 42.1 only
- Opensuse Opensuse: version 13.1 only
- Red Hat Enterprise Linux Desktop: version 6.0 only
- Red Hat Enterprise Linux Eus: version 6.7 only
- Red Hat Enterprise Linux Server: version 6.0 only
- Red Hat Enterprise Linux Workstation: version 6.0 only
- Suse Package Hub: affected versions not specified
Published 2016-03-29. Last modified 2026-06-17.