CVE-2015-1360: Google Chrome

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data that is improperly handled during text drawing, related to gpu/GrBitmapTextContext.cpp and gpu/GrDistanceFieldTextContext.cpp, a different vulnerability than CVE-2015-1205.

Affected products

  • Google Chrome: up to and including 40.0.2214.85

Published 2015-01-27. Last modified 2026-06-17.