VULNERABILITY INTELLIGENCE

CVE-2016-1644

CVSS score8.8 HIGH
EPSS probability2.06%
CISA KEVNot currently listed
Published2016-03-13
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

WebKit/Source/core/layout/LayoutObject.cpp in Blink, as used in Google Chrome before 49.0.2623.87, does not properly restrict relayout scheduling, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted HTML document.

Primary references