Executive brief
Google Chromium V8 Engine contains a memory corruption vulnerability due to incorrect handling of complex species. A remote attacker can exploit this via a crafted HTML page to execute arbitrary code on the target system.
Affected products
- Google Chrome prior to 57.0.2987.98
- Google Chrome for Android prior to 57.0.2987.108
- Google V8 Engine prior to 57.0.2987.98
Timeline
- 2017-03-09: patched: Stable channel update for desktop released (57.0.2987.98)
- 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-06-08: disclosed