ZeroHour

CVE-2017-5030

KEV PoC mass

Out-of-Bounds Read in Google Chromium V8 Allows RCE via Crafted HTML Page

CISA: Google Chromium V8 Memory Corruption Vulnerability

CVSS 3.1
8.8 high
EPSS
42%p99
Published
()
KEV added
AI analysis

CVE-2017-5030 is a memory-corruption vulnerability (out-of-bounds read, CWE-125) in the V8 JavaScript engine of Google Chromium, which CISA classifies as enabling remote code execution. It is triggered simply by loading a crafted HTML page, meaning a victim browsing to an attacker-controlled or compromised website is enough to reach the vulnerable engine. A successful attacker gains code execution in the browser process on the victim's machine. Because Chromium V8 underpins many browsers, the flaw affects Google Chrome and, per the CISA description, other Chromium-based browsers such as Microsoft Edge and Opera, on any build that predates the fix. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-06-08 (confirming in-the-wild exploitation), EPSS estimates a 41.7% probability of exploitation within 30 days (99th percentile), and no public proof-of-concept is known; ransomware use is unknown.

What to do: Apply updates per vendor instructions: bring all Chromium-based browsers (Chrome, Edge, Opera, Brave) and Chromium-embedded runtimes (Electron, CEF, kiosk/VDI images, browser-automation containers) to a current release — the underlying fix dates to the February 2017 Chrome 56.0.2924.87 stable update, so any maintained browser is already patched. Audit internet-facing endpoints and frozen/legacy Chromium builds for outdated V8 versions and treat remediation as KEV-priority, even though no public PoC is known and ransomware association is unconfirmed.

Affected
Google Chromium V8 (JavaScript engine)builds prior to the February 2017 fix (fixed in Chrome 56.0.2924.87)
Google Chrome (Chromium-based)versions before the February 2017 stable fix
Microsoft Edge (Chromium-based builds)affected if based on a V8 build predating the fix; exact versions unknown
Opera (Chromium-based)affected if based on a V8 build predating the fix; exact versions unknown
Estimated exposure
massbillions of users/devices (Chrome alone runs on ≈3B+ devices; V8 is also embedded in Edge, Opera, Brave, Electron/CEF apps), though residual exposure today is… — Chromium's V8 is the world's most deployed browser engine — Chrome holds roughly 60–65% of desktop browser market share and billions of mobile users, and V8 is embedded in Edge, Opera, Electron/CEF and headless automation — so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a remote attacker to execute arbitrary code via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googledebianredhat
Products
chrome, debian linux, enterprise linux desktop, enterprise linux server, enterprise linux workstation
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.