CVE-2016-2052: Google Chrome

High severity, CVSS 7.6. EPSS: 1% chance of exploitation in the next 30 days.

Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.

Affected products

Published 2016-01-25. Last modified 2026-06-17.