PatchSiren cyber security CVE debrief
CVE-2016-9650 Google CVE debrief
CVE-2016-9650 is a Google Chrome Blink vulnerability that could let a remote attacker bypass a no-referrer policy by getting a victim to load a crafted HTML page. NVD assigns a medium-severity CVSS 3.0 score of 4.3, and the published record ties the issue to Chrome versions before 55.0.2883.75 on desktop platforms and before 55.0.2883.84 on Android. The practical risk is limited but relevant wherever browser referrer controls are relied on for privacy or workflow separation.
- Vendor
- Product
- Chrome
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-19
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-19
- Advisory updated
- 2026-05-13
Who should care
Organizations running Google Chrome on managed desktops or Android devices, especially security teams that rely on referrer-policy behavior for privacy controls, analytics separation, or internal web app assumptions. End users on affected Chrome versions should also update promptly.
Technical summary
According to the NVD description, Blink in Chrome incorrectly handled iframes, which allowed a remote attacker to bypass a no-referrer policy via a crafted HTML page. The NVD record classifies the weakness as CWE-19 and gives the impact as network-reachable, no privileges required, but requiring user interaction. The supplied CVSS vector is AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N, indicating limited impact and no direct availability effect.
Defensive priority
Medium. The issue is not rated high severity, but it affects a widely deployed browser component and can undermine privacy or security assumptions around referrer handling. Priority should be higher in environments that depend on strict referrer suppression or that have many unmanaged browser clients.
Recommended defensive actions
- Update Google Chrome to a fixed release: 55.0.2883.75 or later on Mac, Windows, and Linux, and 55.0.2883.84 or later on Android.
- Verify fleet-wide browser version compliance using endpoint management or browser management tooling.
- Review any application logic that assumes no-referrer behavior for sensitive navigation flows, and avoid depending on referrer suppression as the only control.
- Keep Chrome auto-update enabled and ensure Android patch deployment reaches managed devices quickly.
- If you maintain internal web apps, test referrer-policy assumptions across browser versions during release validation.
Evidence notes
The NVD record states that Blink in Google Chrome prior to the fixed versions incorrectly handled iframes, enabling a remote attacker to bypass a no-referrer policy via a crafted HTML page. The same record provides the affected version boundary for Chrome CPE entries and lists CVSS 3.0 AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N with CWE-19. The record also points to Chrome release notes, a Chrome bug, and downstream advisories as references.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-9650 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-9650
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-9650 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-9650
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://chromereleases.googleblog.com/2016/12/stable-channel-update-for-desktop.html
-
Source reference
Unverified legacy reference
URL: https://crbug.com/653034
-
Source reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201612-11
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.