Candidate: CVE-2016-1625 PublicDate: 2016-02-14 02:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1625 Description: The Chrome Instant feature in Google Chrome before 48.0.2564.109 does not ensure that a New Tab Page (NTP) navigation target is on the most-visited or suggestions list, which allows remote attackers to bypass intended restrictions via unspecified vectors, related to instant_service.cc and search_tab_helper.cc. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Jann Horn Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N [4.3 MEDIUM] Patches_chromium-browser: upstream_chromium-browser: released (48.0.2564.109) precise_chromium-browser: ignored trusty_chromium-browser: released (48.0.2564.116-0ubuntu0.14.04.1.1111) trusty/esm_chromium-browser: DNE (trusty was released [48.0.2564.116-0ubuntu0.14.04.1.1111]) vivid_chromium-browser: needed vivid/ubuntu-core_chromium-browser: DNE vivid/stable-phone-overlay_chromium-browser: DNE wily_chromium-browser: released (48.0.2564.116-0ubuntu0.15.10.1.1221) devel_chromium-browser: released (48.0.2564.116-0ubuntu1.1229) Patches_oxide-qt: upstream_oxide-qt: not-affected precise_oxide-qt: DNE trusty_oxide-qt: not-affected trusty/esm_oxide-qt: DNE (trusty was not-affected) vivid_oxide-qt: not-affected vivid/ubuntu-core_oxide-qt: DNE vivid/stable-phone-overlay_oxide-qt: not-affected wily_oxide-qt: not-affected devel_oxide-qt: not-affected