Google Chrome contains flaws in the USB Apps API (extensions/api/usb/usb_api.cc) that are triggered when handling various parameters and performing transfer length validation. With a specially crafted extension, a context-dependent attacker can corrupt memory and potentially execute arbitrary code.