CVE-2016-1706

Source
https://cve.org/CVERecord?id=CVE-2016-1706
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-1706.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-1706
Downstream
Related
Published
2016-07-23T19:59:01.590Z
Modified
2026-03-15T14:16:09.948641Z
Severity
  • 9.6 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

The PPAPI implementation in Google Chrome before 52.0.2743.82 does not validate the origin of IPC messages to the plugin broker process that should have come from the browser process, which allows remote attackers to bypass a sandbox protection mechanism via an unexpected message type, related to brokerprocessdispatcher.cc, ppapipluginprocesshost.cc, ppapithread.cc, and renderframemessage_filter.cc.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "51.0.2704.106"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-1706.json"