Junglewise Threat Intelligence

CVE-2018-17463: Google Chromium V8 Remote Code Execution Vulnerability

CVE-2018-17463 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-06-08

Technologies: Google Chromium V8, Microsoft Edge, Opera Software Opera, Google Chrome. Vendors: Google, Microsoft, Opera Software.

Executive brief

An incorrect side effect annotation in the Google Chromium V8 engine allows a remote attacker to execute arbitrary code within a sandbox. The vulnerability is triggered when a user visits a specially crafted HTML page.

Affected products

  • Google V8 prior to 70.0.3538.64
  • Google Chrome prior to 70.0.3538.64
  • Microsoft Edge
  • Opera Software Opera

Timeline

  • 2018-10-16: patched: Stable Channel Update for Desktop (70.0.3538.64) released.
  • 2018-12-18: disclosed: Initial NVD analysis published.
  • 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-06-08: advisory: NVD advisory published.

Related threats