The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own properties, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code that triggers an incorrect cast, related to extensions/renderer/v8_helpers.h and gin/converter.h.
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00014.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00015.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00018.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00028.html
https://code.google.com/p/chromium/issues/detail?id=549986
https://codereview.chromium.org/1433293004
https://security.gentoo.org/glsa/201603-09