Man-in-the-Middle Vulnerability in Google Chrome's Software Removal Tool
CVE-2016-1693
5.3MEDIUM
Key Information:
- Vendor
Debian
- Vendor
- CVE Published:
- 5 June 2016
What is CVE-2016-1693?
In Google Chrome prior to version 51.0.2704.63, a vulnerability exists in the handling of the Software Removal Tool (CCT). The application fails to enforce HTTPS connections when obtaining the tool from dl.google.com, which allows attackers to exploit this oversight. By using a man-in-the-middle attack on an unencrypted HTTP session, remote attackers can successfully spoof the CCT executable. This can lead to unauthorized execution of malicious software under the guise of legitimate tool functionality, posing significant security risks to users.