CVE-2017-5070
KEV PoC massType Confusion in Google Chromium V8 Enables In-Sandbox Code Execution
CISA: Google Chromium V8 Type Confusion Vulnerability
Google Chromium's V8 JavaScript engine contains a type confusion vulnerability (CWE-843) in which the engine mishandles object types, enabling memory corruption when malicious content is processed. An attacker triggers the flaw by luring a user to a specially crafted HTML page whose script drives V8 into the confused state. Successful exploitation yields remote code execution inside the browser's sandbox, which typically serves as the first stage of an attack chain requiring a separate sandbox escape for full system compromise. Anyone using a browser built on affected Chromium V8 is exposed; per CISA this includes Google Chrome, Microsoft Edge, Opera, and other Chromium-based browsers. Exploitation is confirmed: CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2022-06-08 (ransomware use unknown; no public proof-of-concept known), EPSS estimates a 31.2% probability of exploitation within 30 days (98th percentile), and CVSS has not yet been scored.
What to do: Update Google Chrome, Microsoft Edge, Opera, and any other Chromium-based browsers in your fleet to current vendor-patched releases, per CISA's required action to apply updates per vendor instructions; the source data does not enumerate fixed builds, so verify browsers are fully up to date. Audit managed endpoints for outdated browser versions and prioritize internet-facing and high-risk users given KEV-confirmed exploitation and the 31.2% EPSS score. As an interim mitigation, consider restricting JavaScript from untrusted sites until patches are applied.
| Google Chromium V8 engine | — |
| Google Chrome | — |
| Microsoft Edge | — |
| Opera browser | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
- Affected
- Google Chromium V8
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
In the news0 stories
No ingested article mentions this CVE yet.