---
title: "CVE-2016-1675\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2016-1675?format=md
keywords: index, follow
---

# CVE-2016-1675

Publication date 31 May 2016

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**8.8 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2016-1675?format=md#impact-score)

Toggle side navigation

## Description

Blink, as used in Google Chrome before 51.0.2704.63, allows remote
attackers to bypass the Same Origin Policy by leveraging the mishandling of
Document reattachment during destruction, related to FrameLoader.cpp and
LocalFrame.cpp.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| chromium-browser | 16.04 LTS xenial | Fixed 51.0.2704.79-0ubuntu0.16.04.1.1242 |
| 15.10 wily | Ignored end of life |
| 14.04 LTS trusty | Fixed 51.0.2704.79-0ubuntu0.14.04.1.1121 |
| 12.04 LTS precise | Ignored |
| oxide-qt | 16.04 LTS xenial | Fixed 1.15.7-0ubuntu0.16.04.1 |
| 15.10 wily | Fixed 1.15.7-0ubuntu0.15.10.1 |
| 14.04 LTS trusty | Fixed 1.15.7-0ubuntu0.14.04.1 |
| 12.04 LTS precise | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

8.8 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | Required |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 8.8 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1675)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2016-1675)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2016-1675)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2016-1675)

### Related Ubuntu Security Notices (USN)

+ [USN-2992-1](https://usn.ubuntu.com/USN-2992-1)
+ Oxide vulnerabilities
+ 6 June 2016

### Other references

* <http://googlechromereleases.blogspot.com/2016/05/stable-channel-update_25.html>
* <https://www.cve.org/CVERecord?id=CVE-2016-1675>
