CVE-2016-8504
MEDIUMYandex Browser <16.6 - CSRF
Title source: llmDescription
CSRF of synchronization form in Yandex Browser for desktop before version 16.6 could be used by remote attacker to steal saved data in browser profile.
Scores
CVSS v3
4.3
EPSS
0.0009
EPSS Percentile
26.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Classification
CWE
CWE-352
Status
published
Affected Products (2)
yandex/yandex_browser
< 16.6.1.30165
Yandex N.V./Yandex Browser for desktop
< before 16.6 for OSx and Windows
Timeline
Published
Oct 26, 2016
Tracked Since
Feb 18, 2026