base/memory/shared_memory_win.cc in Google Chrome before 38.0.2125.101 on Windows does not properly implement read-only restrictions on shared memory, which allows attackers to bypass a sandbox protection mechanism via unspecified vectors.
https://src.chromium.org/viewvc/chrome?revision=288152&view=revision
https://src.chromium.org/viewvc/chrome?revision=285195&view=revision
http://www.securityfocus.com/bid/70273
http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.html