Executive brief
Google Chrome is a widely used web browser. A security flaw was found in its V8 engine, which handles JavaScript. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially leading to browser crashes or unauthorized access to information.
Technical details
A use-after-free (UAF) vulnerability exists in the V8 JavaScript engine within Google Chrome. The flaw is triggered when the engine incorrectly manages memory objects, allowing a remote attacker to exploit heap corruption. By persuading a user to visit a malicious HTML page, an attacker can trigger the UAF condition. This can lead to a denial-of-service (browser crash) or potentially arbitrary code execution within the context of the browser's sandbox. The issue was resolved in Chrome version 55.0.2883.75 for desktop and 55.0.2883.84 for Android.
Affected products
- Google Chrome < 55.0.2883.75 (Desktop); < 55.0.2883.84 (Android)
- Google Chromium < 55.0.2883.75
Timeline
- 2016-12-01: patched: Chrome 55.0.2883.75 released for desktop
- 2016-12-05: advisory: Gentoo GLSA 201612-11 published
- 2016-12-07: advisory: Red Hat RHSA-2016:2919 published
- 2017-01-19: disclosed: NVD publication date