CVE-2016-5221: Google Chrome

Medium severity, CVSS 6.3. EPSS: 1.1% chance of exploitation in the next 30 days.

Type confusion in libGLESv2 in ANGLE in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android possibly allowed a remote attacker to bypass buffer validation via a crafted HTML page.

Affected products

  • Google Chrome: up to and including 54.0.2840.99

Published 2017-01-19. Last modified 2026-06-17.