browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an erase() call, which causes the erase operation to access data that that erase operation will destroy.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5202.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "54.0.2840.98"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "54.0.2840.99"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "54.0.2840.100"
}
]
}
]