CVE-2015-6778: Google Chrome

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

The CJBig2_SymbolDict class in fxcodec/jbig2/JBig2_SymbolDict.cpp in PDFium, as used in Google Chrome before 47.0.2526.73, allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via a PDF document containing crafted data with JBIG2 compression.

Affected products

  • Google Chrome: up to and including 46.0.2490.86

Published 2015-12-06. Last modified 2026-06-17.