CVE-2016-1706
Last modified
CVE-2016-1706 is a vulnerability of currently unknown severity. The PPAPI implementation in Google Chrome before 52.0.2743.82 does not validate the origin of IPC messages to the plugin broker process that should have come from the browser process, which allows remote attackers to bypass a sandbox protection mechanism via an unexpected message type, related to broker_process_dispatcher.cc, ppapi_plugin_process_host.cc, ppapi_thread.cc, and render_frame_message_filter.cc.. EPSS estimates a 2.43% chance of exploitation in the next 30 days.
Description
The PPAPI implementation in Google Chrome before 52.0.2743.82 does not validate the origin of IPC messages to the plugin broker process that should have come from the browser process, which allows remote attackers to bypass a sandbox protection mechanism via an unexpected message type, related to broker_process_dispatcher.cc, ppapi_plugin_process_host.cc, ppapi_thread.cc, and render_frame_message_filter.cc.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Chrome | <= 51.0.2704.106 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-1706?
How severe is CVE-2016-1706?
How do I fix CVE-2016-1706?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-1700extensions/renderer/runtime_custom_bindings.cc in Google Chr…
- CVE-2016-1701The Autofill implementation in Google Chrome before 51.0.270…
- CVE-2016-1702The SkRegion::readFromMemory function in core/SkRegion.cpp i…
- CVE-2016-1703Multiple unspecified vulnerabilities in Google Chrome before…
- CVE-2016-1704Multiple unspecified vulnerabilities in Google Chrome before…
- CVE-2016-1705Multiple unspecified vulnerabilities in Google Chrome before…
- CVE-2016-1707ios/web/web_state/ui/crw_web_controller.mm in Google Chrome …
- CVE-2016-1708The Chrome Web Store inline-installation implementation in t…
- CVE-2016-1709Heap-based buffer overflow in the ByteArray::Get method in d…
- CVE-2016-1710The ChromeClientImpl::createWindow method in WebKit/Source/w…
- CVE-2016-1711WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used …
- CVE-2016-1712Palo Alto Networks PAN-OS before 5.0.19, 5.1.x before 5.1.12…
Are you affected by CVE-2016-1706?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
