AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2016-1658

MEDIUM · CVSS 4.3 EPSS 1.40%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2016-04-18 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2016-1658
Severity
MEDIUM
CVSS
4.3
EPSS
1.40%
Chrome

Original NVD Description

The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.