CVE-2014-1730
Google V8, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly store internationalization metadata, which allows remote attackers to bypass intended access restrictions by leveraging…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.08%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Google V8, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly store internationalization metadata, which allows remote attackers to bypass intended access restrictions by leveraging "type confusion" and reading property values, related to i18n.js and runtime.cc.
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
- EPSS
- 3.08% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-843
- Affected
- google/chrome
- Source
- chrome-cve-admin@google.com
References
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.html
- http://lists.opensuse.org/opensuse-updates/2014-05/msg00049.html
- http://lists.opensuse.org/opensuse-updates/2014-05/msg00050.html
- http://secunia.com/advisories/58301
- http://secunia.com/advisories/60372
- http://security.gentoo.org/glsa/glsa-201408-16.xml
- http://www.debian.org/security/2014/dsa-2920
- https://code.google.com/p/chromium/issues/detail?id=354967
- https://code.google.com/p/v8/source/detail?r=20375
- https://code.google.com/p/v8/source/detail?r=20377
- https://code.google.com/p/v8/source/detail?r=20388
- https://code.google.com/p/v8/source/detail?r=20593
- https://code.google.com/p/v8/source/detail?r=20595
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.html
- http://lists.opensuse.org/opensuse-updates/2014-05/msg00049.html
- http://lists.opensuse.org/opensuse-updates/2014-05/msg00050.html
- http://secunia.com/advisories/58301
- http://secunia.com/advisories/60372
- http://security.gentoo.org/glsa/glsa-201408-16.xml
- http://www.debian.org/security/2014/dsa-2920
- https://code.google.com/p/chromium/issues/detail?id=354967
- https://code.google.com/p/v8/source/detail?r=20375
- https://code.google.com/p/v8/source/detail?r=20377
- https://code.google.com/p/v8/source/detail?r=20388
- https://code.google.com/p/v8/source/detail?r=20593
- https://code.google.com/p/v8/source/detail?r=20595
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.