SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2016-5198

Google Chromium V8 Out-of-Bounds Memory Vulnerability

KEVHIGH 8.8EPSS 34.8%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading to code execution, via a crafted HTML page.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
34.81% probability · 98th percentile
CISA KEV
Listed 8 June 2022 · due 22 June 2022
Weakness
CWE-787
Affected
google/chrome · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation
Source
chrome-cve-admin@google.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2016-5198

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.