Executive brief
The Google Chromium V8 engine contained incorrect optimization assumptions, leading to an out-of-bounds memory access vulnerability. A remote attacker could exploit this via a crafted HTML page to perform arbitrary read/write operations and execute arbitrary code.
Affected products
- Google V8 prior to 54.0.2840.90 for Linux, 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac
- Google Chrome prior to 54.0.2840.90 (Linux), 54.0.2840.85 (Android), 54.0.2840.87 (Windows/Mac)
Timeline
- 2016-11-01: patched: Stable channel update for desktop released to address the issue.
- 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-06-08: disclosed: NVD publication date.