Junglewise Threat Intelligence

CVE-2017-5030: Google Chromium V8 Memory Corruption Vulnerability

CVE-2017-5030 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-06-08

Technologies: Google Chrome for Android, Google Chromium V8, Google Chrome. Vendors: Google.

Executive brief

Google Chromium V8 Engine contains a memory corruption vulnerability due to incorrect handling of complex species. A remote attacker can exploit this via a crafted HTML page to execute arbitrary code on the target system.

Affected products

  • Google Chrome prior to 57.0.2987.98
  • Google Chrome for Android prior to 57.0.2987.108
  • Google V8 Engine prior to 57.0.2987.98

Timeline

  • 2017-03-09: patched: Stable channel update for desktop released (57.0.2987.98)
  • 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-06-08: disclosed

Related threats