CVE-2016-1655

HIGH

Google Chrome <50.0.2661.75 - Use After Free

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-1655. PoCs published by OpenSISE.

AI-analyzed exploit summary The repository contains a minimal JavaScript snippet that removes a frame element, which is unrelated to the actual exploitation of CVE-2016-1655 (a UAF vulnerability in Adobe Flash). No functional exploit code is present.

Description

Google Chrome before 50.0.2661.75 does not properly consider that frame removal may occur during callback execution, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted extension.

Exploits (1)

github STUB 31 stars
by OpenSISE · cpoc
https://github.com/OpenSISE/CVE_PoC_Collect/tree/master/Browser/CVE-2016-1655

The repository contains a minimal JavaScript snippet that removes a frame element, which is unrelated to the actual exploitation of CVE-2016-1655 (a UAF vulnerability in Adobe Flash). No functional exploit code is present.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Adobe Flash Player
No auth needed
Prerequisites: None
devstral-2 · analyzed Feb 27, 2026 Full analysis →

References (11)

Core 11
Core References
Patch x_refsource_confirm
https://codereview.chromium.org/1642283002
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-0638.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2016/dsa-3549
Issue Tracking x_refsource_confirm
https://crbug.com/582008
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2955-1
Release Notes, Vendor Advisory x_refsource_confirm
http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_13.html
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201605-02

Scores

CVSS v3 8.8
EPSS 0.0214
EPSS Percentile 79.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

Status published
Products (7)
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 15.10
canonical/ubuntu_linux 16.04
debian/debian_linux 8.0
google/chrome < 49.0.2623.112
opensuse/leap 42.1
suse/linux_enterprise 12.0
Published Apr 18, 2016
Tracked Since Feb 18, 2026