CVE-2016-5139: Google Chrome

High severity, CVSS 7.6. EPSS: 1.3% chance of exploitation in the next 30 days.

Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JPEG 2000 data.

Affected products

  • Google Chrome: version 52.0.2743.82 only

Published 2016-08-07. Last modified 2026-06-17.