SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-1730

Google V8, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly store internationalization metadata, which allows remote attackers to bypass intended access restrictions by leveraging…

HIGH 7.8EPSS 3.08%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (3.08%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Google V8, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly store internationalization metadata, which allows remote attackers to bypass intended access restrictions by leveraging "type confusion" and reading property values, related to i18n.js and runtime.cc.

CVSS 2.0
7.8 HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
EPSS
3.08% probability · 87th percentile
CISA KEV
Not listed
Weakness
CWE-843
Affected
google/chrome
Source
chrome-cve-admin@google.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.