CVE-2016-5198
KEV PoC massOut-of-Bounds Memory Access in Google Chromium V8 Enables Remote Code Execution
CISA: Google Chromium V8 Out-of-Bounds Memory Vulnerability
CVE-2016-5198 is an out-of-bounds memory access (out-of-bounds read/write, CWE-125/CWE-787) in the V8 JavaScript engine used by Google Chromium. An attacker triggers it by inducing a user to open a crafted HTML page in a vulnerable Chromium-based browser, causing the engine to read or write outside allocated memory. Successful exploitation allows a remote attacker to gain read/write primitives that can escalate to code execution in the browser context. Anyone using a browser or application built on the affected Chromium V8 engine is exposed, including Google Chrome, Microsoft Edge, Opera, and other Chromium derivatives per CISA's description. The flaw is listed in the CISA KEV (added 2022-06-08), indicating known exploitation in the wild, though no public proof-of-concept is known, ransomware association is unknown, and CVSS has not been scored; EPSS estimates a 34.8% probability of exploitation within 30 days (98th percentile).
What to do: Apply vendor-supplied updates for all Chromium-based browsers (Chrome, Edge, Opera) and any Chromium-embedded applications per vendor instructions, as CISA's required action specifies; verify browser versions via each product's About/settings page and prioritize endpoints used to browse untrusted content. The KEV listing confirms active exploitation, so treat patching as urgent; note that specific fixed version numbers are not provided in the source data and ransomware linkage is unknown.
| Google Chromium V8 (JavaScript engine) | — |
| Google Chrome (Chromium-based, per CISA description) | — |
| Microsoft Edge (Chromium-based, per CISA description) | — |
| Opera (Chromium-based, per CISA description) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading to code execution, via a crafted HTML page.
- Affected
- Google Chromium V8
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
In the news0 stories
No ingested article mentions this CVE yet.