CVE-2015-1221: Google Chrome

High severity, CVSS 7.5. EPSS: 2.5% chance of exploitation in the next 30 days.

Use-after-free vulnerability in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect ordering of operations in the Web SQL Database thread relative to Blink's main thread, related to the shutdown function in web/WebKit.cpp.

Affected products

  • Google Chrome: up to and including 40.0.2214.115

Published 2015-03-09. Last modified 2026-06-17.