A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
https://www.exploit-db.com/exploits/42175/
https://security.gentoo.org/glsa/201612-11
https://chromereleases.googleblog.com/2016/12/stable-channel-update-for-desktop.html