Junglewise Threat Intelligence

CVE-2016-5198: Google Chromium V8 Out-of-Bounds Memory Vulnerability

CVE-2016-5198 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-06-08

Technologies: Google Chromium V8, Google Chrome. Vendors: Google.

Executive brief

The Google Chromium V8 engine contained incorrect optimization assumptions, leading to an out-of-bounds memory access vulnerability. A remote attacker could exploit this via a crafted HTML page to perform arbitrary read/write operations and execute arbitrary code.

Affected products

  • Google V8 prior to 54.0.2840.90 for Linux, 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac
  • Google Chrome prior to 54.0.2840.90 (Linux), 54.0.2840.85 (Android), 54.0.2840.87 (Windows/Mac)

Timeline

  • 2016-11-01: patched: Stable channel update for desktop released to address the issue.
  • 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-06-08: disclosed: NVD publication date.

Related threats