ZeroHour

CVE-2016-1646

KEV PoC mass

Out-of-Bounds Read in Google Chromium V8 JavaScript Engine

CISA: Google Chromium V8 Out-of-Bounds Read Vulnerability

CVSS 3.1
8.8 high
EPSS
48%p99
Published
()
KEV added
AI analysis

Google's Chromium V8 JavaScript engine contains an out-of-bounds read (CWE-119), meaning the engine reads memory beyond the bounds of an allocated buffer while processing JavaScript. A remote attacker can trigger the flaw by getting a user's browser to execute crafted JavaScript, typically by luring them to a malicious or compromised web page. Successful exploitation primarily causes a denial of service (browser crash), though the advisory notes that other, unspecified impacts may also be possible. Any user of a Chromium-based browser, including Google Chrome, Microsoft Edge, and Opera, was potentially affected while running a vulnerable V8 build. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-06-08 (required action: apply updates per vendor instructions), no public proof-of-concept is known, ransomware use is unknown, and EPSS assigns a 48.1% probability of exploitation within 30 days (99th percentile).

What to do: Apply updates per vendor instructions: bring Google Chrome, Chromium, Opera, and any other Chromium-based browsers or V8-embedding applications up to a current vendor-supported release (this 2016 flaw is remediated in all modern builds). Because the vulnerability is on CISA's KEV list, treat patching of managed and internet-facing systems as required and verify browser/defense versions directly (e.g., via chrome://version or the application's about page) for anything still pinned to 2016-era builds. For products that bundle Chromium or V8 (kiosks, Electron-style apps, appliances), update the bundled engine rather than relying on browser-level updates.

Affected
Google Chromium V8
Google Chrome (Chromium-based)
Microsoft Edge (Chromium-based)
Opera (Chromium-based)
Estimated exposure
mass≈1–3 billion browser users (Chrome alone surpassed 1 billion active users around 2016 and ~3 billion more recently; V8 also ships in Chromium-based Edge and… — Based on Google's publicly reported Chrome active-user base exceeding 1 billion at the time of the flaw and V8's ubiquity across Chromium-family browsers and embedded runtimes, the plausibly exposed population is on the order of billions…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code.

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
debiancanonicalgooglesuseopensuseredhat
Products
debian linux, ubuntu linux, chrome, package hub, leap, opensuse, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux workstation
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news