CVE-2016-8504

MEDIUM

Yandex Browser <16.6 - CSRF

Title source: llm

Description

CSRF of synchronization form in Yandex Browser for desktop before version 16.6 could be used by remote attacker to steal saved data in browser profile.

Scores

CVSS v3 4.3
EPSS 0.0009
EPSS Percentile 26.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Classification

CWE
CWE-352
Status published

Affected Products (2)

yandex/yandex_browser < 16.6.1.30165
Yandex N.V./Yandex Browser for desktop < before 16.6 for OSx and Windows

Timeline

Published Oct 26, 2016
Tracked Since Feb 18, 2026