CVE-2016-5184: Google Chrome
High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.
PDFium in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly handled object lifecycles in CFFL_FormFillter::KillFocusForAnnot, which allowed a remote attacker to potentially exploit heap corruption via crafted PDF files.
Affected products
- Google Chrome: up to and including 53.0.2785.143
Published 2016-12-18. Last modified 2026-06-17.