CVE-2016-5182: Google Chrome

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android had insufficient validation in bitmap handling, which allowed a remote attacker to potentially exploit heap corruption via crafted HTML pages.

Affected products

  • Google Chrome: up to and including 53.0.2785.143

Published 2016-12-18. Last modified 2026-06-17.