CVE-2017-5030
KEV PoC massOut-of-Bounds Read in Google Chromium V8 Allows RCE via Crafted HTML Page
CISA: Google Chromium V8 Memory Corruption Vulnerability
CVE-2017-5030 is a memory-corruption vulnerability (out-of-bounds read, CWE-125) in the V8 JavaScript engine of Google Chromium, which CISA classifies as enabling remote code execution. It is triggered simply by loading a crafted HTML page, meaning a victim browsing to an attacker-controlled or compromised website is enough to reach the vulnerable engine. A successful attacker gains code execution in the browser process on the victim's machine. Because Chromium V8 underpins many browsers, the flaw affects Google Chrome and, per the CISA description, other Chromium-based browsers such as Microsoft Edge and Opera, on any build that predates the fix. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-06-08 (confirming in-the-wild exploitation), EPSS estimates a 41.7% probability of exploitation within 30 days (99th percentile), and no public proof-of-concept is known; ransomware use is unknown.
What to do: Apply updates per vendor instructions: bring all Chromium-based browsers (Chrome, Edge, Opera, Brave) and Chromium-embedded runtimes (Electron, CEF, kiosk/VDI images, browser-automation containers) to a current release — the underlying fix dates to the February 2017 Chrome 56.0.2924.87 stable update, so any maintained browser is already patched. Audit internet-facing endpoints and frozen/legacy Chromium builds for outdated V8 versions and treat remediation as KEV-priority, even though no public PoC is known and ransomware association is unconfirmed.
| Google Chromium V8 (JavaScript engine) | builds prior to the February 2017 fix (fixed in Chrome 56.0.2924.87) |
| Google Chrome (Chromium-based) | versions before the February 2017 stable fix |
| Microsoft Edge (Chromium-based builds) | affected if based on a V8 build predating the fix; exact versions unknown |
| Opera (Chromium-based) | affected if based on a V8 build predating the fix; exact versions unknown |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a remote attacker to execute arbitrary code via a crafted HTML page.
- Affected
- Google Chromium V8
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
In the news0 stories
No ingested article mentions this CVE yet.