V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading to code execution, via a crafted HTML page.
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "54.0.2840.90"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "54.0.2840.85"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "54.0.2840.87"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.0"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5198.json"