VulnerabilityAnalyzed
CVE-2018-17480
Google Chromium V8 Out-of-Bounds Write Vulnerability
KEVHIGH 8.8EPSS 35.6%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 35.64% probability · 98th percentile
- CISA KEV
- Listed 8 June 2022 · due 22 June 2022
- Weakness
- CWE-787
- Affected
- google/chrome · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation · debian/debian linux
- Source
- chrome-cve-admin@google.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2018-17480
References
- http://www.securityfocus.com/bid/106084Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3803Third Party Advisory
- https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.htmlVendor Advisory
- https://crbug.com/905940Exploit, Issue Tracking
- https://security.gentoo.org/glsa/201908-18Third Party Advisory
- https://www.debian.org/security/2018/dsa-4352Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/106084Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3803Third Party Advisory
- https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.htmlVendor Advisory
- https://crbug.com/905940Exploit, Issue Tracking
- https://security.gentoo.org/glsa/201908-18Third Party Advisory
- https://www.debian.org/security/2018/dsa-4352Mailing List, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-17480US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.