Medium severity6.5NVD Advisory· Published Jun 5, 2016· Updated May 6, 2026
CVE-2016-1687
CVE-2016-1687
Description
The renderer implementation in Google Chrome before 51.0.2704.63 does not properly restrict public exposure of classes, which allows remote attackers to obtain sensitive information via vectors related to extensions.
Affected products
8- cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:suse:linux_enterprise:12.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
12- googlechromereleases.blogspot.com/2016/05/stable-channel-update_25.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-05/msg00062.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-05/msg00063.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-06/msg00005.htmlnvd
- www.debian.org/security/2016/dsa-3590nvd
- www.securityfocus.com/bid/90876nvd
- www.securitytracker.com/id/1035981nvd
- access.redhat.com/errata/RHSA-2016:1190nvd
- codereview.chromium.org/1938123002nvd
- codereview.chromium.org/1939833003nvd
- crbug.com/603748nvd
- security.gentoo.org/glsa/201607-07nvd
News mentions
0No linked articles in our index yet.