CVE DATABASE / CVE-2016-1646
CVE-2016-1646
Google Chromium V8 Out-of-Bounds Read Vulnerability
Confirmed exploited in the wild. Added 2022-06-08.
Federal remediation due 2022-06-22.
Required action: Apply updates per vendor instructions.
Summary
The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code.
CVSS 3.1 breakdown
| Base score | 8.8 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| Attack vector | NETWORK |
| Attack complexity | LOW |
| Privileges required | NONE |
| User interaction | REQUIRED |
| Scope | UNCHANGED |
| Confidentiality | HIGH |
| Integrity | HIGH |
| Availability | HIGH |
Weakness type (CWE)
Affected products
Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.
References
- http://googlechromereleases.blogspot.com/2016/03/stable-channel-update_24.html
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00039.html
- http://rhn.redhat.com/errata/RHSA-2016-0525.html
- http://www.debian.org/security/2016/dsa-3531
- http://www.securitytracker.com/id/1035423
- http://www.ubuntu.com/usn/USN-2955-1
- https://code.google.com/p/chromium/issues/detail?id=594574
- https://codereview.chromium.org/1804963002/
- https://security.gentoo.org/glsa/201605-02
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-1646
Data: NIST NVD + CISA KEV. NVD last modified 2026-04-21. Always verify against the vendor advisory before acting.