ZeroHour

CVE-2018-17480

KEV PoC mass

Out-of-Bounds Write in Google Chromium V8 Enables Sandboxed Code Execution

CISA: Google Chromium V8 Out-of-Bounds Write Vulnerability

CVSS 3.1
8.8 high
EPSS
36%p98
Published
()
KEV added
AI analysis

CVE-2018-17480 is an out-of-bounds write (CWE-787) in Google's Chromium V8 JavaScript engine, the component that executes web page scripts in Chromium-based browsers. An attacker triggers it by inducing a user to load a crafted HTML page, causing V8 to write past the end of an in-memory buffer in the browser's renderer process. A successful attacker can execute code inside the browser's renderer sandbox; escaping to fully compromise the underlying system would generally require a separate sandbox-escape bug. Anyone using browsers or applications built on the affected Chromium/V8 code is affected, and CISA notes this could include Google Chrome, Microsoft Edge, and Opera. The flaw is listed in CISA's KEV catalog (added 2022-06-08), confirming exploitation in the wild, with a 35.6% EPSS probability of exploitation within 30 days (98th percentile), no public proof-of-concept known, and no confirmed ransomware association.

What to do: Follow CISA's required action and update Google Chrome, Microsoft Edge (Chromium builds), Opera, and any other Chromium- or V8-embedding software to the latest vendor releases, which incorporate the patched V8; no specific version numbers are provided in the source data. Verify update status via each browser's about/settings page and inventory any applications that embed Chromium/V8 on the network. Because the attack vector is loading a crafted web page, web content filtering reduces exposure, but patching is the definitive fix.

Affected
Google Chromium V8 (JavaScript engine)
Google Chrome (Chromium-based browser)
Microsoft Edge (Chromium builds)
Opera (Chromium-based browser)
Estimated exposure
massbillions of users (Chromium's V8 engine underpins Chrome, Edge, and Opera, with Chrome alone on the order of 3B+ users) — Chromium's V8 is the dominant desktop browser engine, shipped in browsers with a combined user base measured in billions; present-day exposure is concentrated in unmanaged or legacy Chromium builds that missed the 2018-era fixes.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googleredhatdebian
Products
chrome, enterprise linux desktop, enterprise linux server, enterprise linux workstation, debian linux
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.