CVE-2015-6582: Google Chrome

Medium severity, CVSS 6.8. EPSS: 0.9% chance of exploitation in the next 30 days.

The decompose function in platform/transforms/TransformationMatrix.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not verify that a matrix inversion succeeded, which allows remote attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted web site.

Affected products

  • Google Chrome: up to and including 44.0.2403

Published 2015-09-03. Last modified 2026-06-17.