Executive brief
An incorrect side effect annotation in the Google Chromium V8 engine allows a remote attacker to execute arbitrary code within a sandbox. The vulnerability is triggered when a user visits a specially crafted HTML page.
Affected products
- Google V8 prior to 70.0.3538.64
- Google Chrome prior to 70.0.3538.64
- Microsoft Edge
- Opera Software Opera
Timeline
- 2018-10-16: patched: Stable Channel Update for Desktop (70.0.3538.64) released.
- 2018-12-18: disclosed: Initial NVD analysis published.
- 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-06-08: advisory: NVD advisory published.