CVE-2016-1675: Canonical Ubuntu Linux
High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.
Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy by leveraging the mishandling of Document reattachment during destruction, related to FrameLoader.cpp and LocalFrame.cpp.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 15.10 only; version 16.04 only
- Debian Debian Linux: version 8.0 only
- Google Chrome: up to and including 50.0.2661.102
- Opensuse Leap: version 42.1 only
- Opensuse Opensuse: version 13.2 only
- Red Hat Enterprise Linux Desktop: version 6.0 only
- Red Hat Enterprise Linux Server: version 6.0 only
- Red Hat Enterprise Linux Workstation: version 6.0 only
- Suse Linux Enterprise: version 12.0 only
Published 2016-06-05. Last modified 2026-06-17.