V8 in Google Chrome prior to 54.0.2840.98 for Mac, and 54.0.2840.99 for Windows, and 54.0.2840.100 for Linux, and 55.0.2883.84 for Android incorrectly applied type rules, which allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
https://security.gentoo.org/glsa/201611-16
https://chromereleases.googleblog.com/2016/11/stable-channel-update-for-desktop_9.html
http://www.securitytracker.com/id/1037273