SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2016-1646

Google Chromium V8 Out-of-Bounds Read Vulnerability

KEVHIGH 8.8EPSS 48.1%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
48.11% probability · 99th percentile
CISA KEV
Listed 8 June 2022 · due 22 June 2022
Weakness
CWE-125
Affected
debian/debian linux · canonical/ubuntu linux · google/chrome · suse/package hub · opensuse/leap · opensuse/opensuse · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux workstation
Source
chrome-cve-admin@google.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2016-1646

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.