CVE-2015-1206: Google Chrome

Medium severity, CVSS 5.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Heap-based buffer overflow in Google Chrome before M40 allows remote attackers to cause a denial of service (unpaged memory write and process crash) via a crafted MP4 file.

Affected products

  • Google Chrome: up to and including 41.0.2251.0

Published 2017-10-06. Last modified 2026-06-17.