CVE-2016-8505: Yandex Yandex.browser

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

XSS in Yandex Browser BookReader in Yandex browser for desktop for versions before 16.6. could be used by remote attacker for evaluation arbitrary javascript code.

Affected products

  • Yandex Yandex.browser: up to and including 16.4.0.94.4

Published 2016-10-26. Last modified 2026-06-17.