A leak of privateClass in the extensions API in Google Chrome prior to 54.0.2840.100 for Linux, and 54.0.2840.99 for Windows, and 54.0.2840.98 for Mac allowed a remote attacker to access privileged JavaScript code via a crafted HTML page.
https://security.gentoo.org/glsa/201611-16
https://chromereleases.googleblog.com/2016/11/stable-channel-update-for-desktop_9.html
http://www.securitytracker.com/id/1037273