Candidate: CVE-2016-1632 PublicDate: 2016-03-06 02:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1632 http://googlechromereleases.blogspot.ca/2016/03/stable-channel-update.html Description: The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own properties, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code that triggers an incorrect cast, related to extensions/renderer/v8_helpers.h and gin/converter.h. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_chromium-browser: upstream_chromium-browser: released (49.0.2623.75) precise_chromium-browser: ignored trusty_chromium-browser: released (49.0.2623.87-0ubuntu0.14.04.1.1112) trusty/esm_chromium-browser: DNE (trusty was released [49.0.2623.87-0ubuntu0.14.04.1.1112]) vivid/ubuntu-core_chromium-browser: DNE vivid/stable-phone-overlay_chromium-browser: DNE wily_chromium-browser: released (49.0.2623.87-0ubuntu0.15.10.1.1222) devel_chromium-browser: released (49.0.2623.87-0ubuntu1.1232) Patches_oxide-qt: upstream_oxide-qt: not-affected precise_oxide-qt: DNE trusty_oxide-qt: not-affected trusty/esm_oxide-qt: DNE (trusty was not-affected) vivid/ubuntu-core_oxide-qt: DNE vivid/stable-phone-overlay_oxide-qt: not-affected wily_oxide-qt: not-affected devel_oxide-qt: not-affected