Junglewise Threat Intelligence

CVE-2017-5070: Google Chromium V8 Type Confusion Vulnerability

CVE-2017-5070 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-06-08

Technologies: Google Chromium V8, Google Chrome for Android, Google Chrome. Vendors: Google.

Executive brief

A type confusion vulnerability in the V8 engine of Google Chromium allows a remote attacker to execute arbitrary code within a sandbox. The exploit is typically delivered via a specially crafted HTML page and affects multiple browsers based on Chromium, including Chrome, Edge, and Opera.

Affected products

  • Google Chrome prior to 59.0.3071.86
  • Google Chrome for Android prior to 59.0.3071.92
  • Google V8 Engine

Timeline

  • 2017-06-05: patched: Stable channel update for desktop released
  • 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-06-08: disclosed: NVD publication date
  • 2022-06-08: exploited: Reported as exploited in the wild per CISA KEV catalog

Related threats