Executive brief
An integer overflow vulnerability exists in the Google Chromium V8 engine when computing the required allocation size for new JavaScript objects. A remote attacker can exploit this via a crafted HTML page to cause heap corruption, potentially leading to arbitrary code execution.
Affected products
- Google Chrome prior to 65.0.3325.146
- Google V8 Engine
- Microsoft Edge
- Opera Software Opera
Timeline
- 2018-03-06: patched: Stable Channel Update for Desktop (65.0.3325.146) released.
- 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-06-08: disclosed: NVD publication date.
- 2022-06-08: exploited: Confirmed as exploited in the wild per CISA KEV.