Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts a "tapjacking" attack.
https://security.gentoo.org/glsa/201506-04
https://codereview.chromium.org/868123002
https://codereview.chromium.org/717573004
https://codereview.chromium.org/660663002
https://codereview.chromium.org/628763003
http://www.debian.org/security/2015/dsa-3238
http://ubuntu.com/usn/usn-2570-1
http://rhn.redhat.com/errata/RHSA-2015-0816.html
http://lists.opensuse.org/opensuse-updates/2015-11/msg00024.html
http://lists.opensuse.org/opensuse-updates/2015-04/msg00040.html
http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.html