ZeroHour

CVE-2018-17463

KEV PoC ×2mass

Type Confusion RCE in Google Chrome/Chromium V8 JavaScript Engine

CISA: Google Chromium V8 Remote Code Execution Vulnerability

CVSS 3.1
8.8 high
EPSS
85%p100
Published
()
KEV added
AI analysis

Google Chrome and Chromium's V8 JavaScript engine, prior to the Chrome 70.0.3538.64 release, contained an incorrect side-effect annotation that corrupts type information during optimization (a type confusion reachable via Object.create), allowing arbitrary code execution inside the browser sandbox. An attacker triggers the flaw by persuading a user to open a crafted HTML page; successful exploitation yields remote code execution running with the browser's privileges, though still confined by the Chrome sandbox. Anyone running Chrome or Chromium before 70.0.3538.64 was affected, including the chromium packages shipped in Red Hat Enterprise Linux and Debian. A public proof of concept covering Chrome 67-69 is available, EPSS assigns an ~85% 30-day exploitation probability (top percentile), and CISA added the issue to the Known Exploited Vulnerabilities catalog on 2022-06-08, confirming exploitation in the wild.

What to do: Update Chrome to 70.0.3538.64 or later (any current release is patched) and apply the latest chromium/chromium-browser security updates on Red Hat Enterprise Linux and Debian. Inventory endpoints and managed browsers for Chrome/Chromium builds older than 70 and verify auto-update is enabled; because exploitation requires user interaction with a crafted page, user awareness and web filtering provide additional defense.

Affected
google chromeprior to 70.0.3538.64
google Chromium V8V8 versions in Chromium prior to the fix in Chrome 70.0.3538.64
redhat enterprise linux desktopchromium packages shipping vulnerable V8, prior to vendor chromium security updates
redhat enterprise linux serverchromium packages shipping vulnerable V8, prior to vendor chromium security updates
redhat enterprise linux workstationchromium packages shipping vulnerable V8, prior to vendor chromium security updates
debian linuxchromium-browser packages shipping vulnerable V8, prior to vendor security updates
Estimated exposure
mass~1 billion+ users at disclosure (Chrome's ~60% desktop browser share in 2018); residual exposure now limited to unpatched legacy installs — Chrome was the dominant desktop browser with well over a billion users when the flaw was patched in October 2018, so the affected population was massive at disclosure, although Chrome auto-updates mean only long-unpatched or embedded…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googleredhatdebian
Products
chrome, enterprise linux desktop, enterprise linux server, enterprise linux workstation, debian linux
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.