High severity8.8NVD Advisory· Published Sep 11, 2016· Updated May 6, 2026
CVE-2016-5150
CVE-2016-5150
Description
WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, has an Indexed Database (aka IndexedDB) API implementation that does not properly restrict key-path evaluation, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted JavaScript code that leverages certain side effects.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
12- lists.opensuse.org/opensuse-security-announce/2016-09/msg00003.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-09/msg00004.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-09/msg00008.htmlnvd
- lists.opensuse.org/opensuse-updates/2016-09/msg00073.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-1854.htmlnvd
- www.debian.org/security/2016/dsa-3660nvd
- www.securityfocus.com/bid/92717nvd
- www.securitytracker.com/id/1036729nvd
- codereview.chromium.org/2255413004/nvd
- crbug.com/637963nvd
- googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.htmlnvd
- security.gentoo.org/glsa/201610-09nvd
News mentions
0No linked articles in our index yet.