Back

HIGH KEV

chromium-browser: out-of-bounds read in V8

Published Mar 29, 2016 ·Due Jun 22, 2022

Description

The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Mar 29, 2016
Updated Oct 21, 2025
Reserved Jan 12, 2016
CISA Vulnrichment
Updated Jan 29, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Mar 24, 2016