CVE-2016-2052: Google Chrome
High severity, CVSS 7.6. EPSS: 1% chance of exploitation in the next 30 days.
Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.
Affected products
- Google Chrome: up to and including 47.0.2526.106
- Harfbuzz Project Harfbuzz: up to and including 1.0.5
Published 2016-01-25. Last modified 2026-06-17.