CVE-2015-6764: Debian Linux

Critical severity, CVSS 9.8. EPSS: 5.7% chance of exploitation in the next 30 days.

The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted JavaScript code.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Google Chrome: up to and including 46.0.2490.86
  • Node.js Node.js: from 4.0.0, up to and including 4.1.2; from 4.2.0, before 4.2.3 (fixed in 4.2.3); from 5.0.0, up to and including 5.1.1

Published 2015-12-06. Last modified 2026-06-17.