Chrome has announced plans to enable CFG recently. It indeed has value, especially when coupled with CET, however, supporting a complicated mitigation like CFG effectively is not just simply enabling some compiler options, there is more work to do.In this presentation, more than ten CFG bypass techniques will be reviewed, and then examined in Chrome to see if they are still valid to bypass CFG directly, that is to say, hijack a protected function pointer to execute arbitrary code.Finally, some suggestions for improvement will be given to prevent these bypass techniques and make Chrome more secure.