CVE-2016-5202: Google Chrome

Critical severity, CVSS 9.1. EPSS: 0.8% chance of exploitation in the next 30 days.

browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an erase() call, which causes the erase operation to access data that that erase operation will destroy.

Affected products

  • Google Chrome: before 54.0.2840.98 (fixed in 54.0.2840.98); before 54.0.2840.99 (fixed in 54.0.2840.99); before 54.0.2840.100 (fixed in 54.0.2840.100)

Published 2019-10-25. Last modified 2026-06-17.