CVE-2016-1649

The Program::getUniformInternal function in Program.cpp in libANGLE, as used in Google Chrome before 49.0.2623.108, does not properly handle a certain data-type mismatch, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted shader stages.

Date published : 2016-03-29

http://googlechromereleases.blogspot.com/2016/03/stable-channel-update_24.html

https://chromium-review.googlesource.com/334448