CVE-2016-1670

MEDIUM

Google Chrome <50.0.2661.102 - RCE

Title source: llm

Description

Race condition in the ResourceDispatcherHostImpl::BeginRequest function in content/browser/loader/resource_dispatcher_host_impl.cc in Google Chrome before 50.0.2661.102 allows remote attackers to make arbitrary HTTP requests by leveraging access to a renderer process and reusing a request ID.

Scores

CVSS v3 5.3
EPSS 0.0068
EPSS Percentile 71.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N

Classification

CWE
CWE-362
Status draft

Affected Products (3)

google/chrome < 50.0.2661.87
opensuse/opensuse
debian/debian_linux

Timeline

Published May 14, 2016
Tracked Since Feb 18, 2026