CVE-2016-1696: Debian Linux

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Google Chrome: up to and including 51.0.2704.63
  • Opensuse Leap: version 42.1 only
  • Opensuse Opensuse: version 13.2 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only
  • Suse Linux Enterprise: version 12.0 only

Published 2016-06-05. Last modified 2026-06-17.