CVE-2018-17463highunder attack

CVE-2018-17463: high-severity vulnerability in Google Chrome

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 8.8epss 85%
from disclosure to weapon481 days
Published on NVDNov 14
1st PoC+481d
metasploitSep 25
CISA KEV+1302d
exploitation probability
85%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
6 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
3 products (12 components)
Red Hat Enterprise Linux Desktop Supplementary (v. 6) · Red Hat Enterprise Linux Server Supplementary (v. 6) · Red Hat Enterprise Linux Workstation Supplementary (v. 6)
Action required by CISAfederal deadline: 2022-06-22

Apply updates per vendor instructions.

In short

A flaw in Chrome's V8 JavaScript engine incorrectly marked certain operations as safe, allowing attackers to run malicious code within the browser's sandbox through a specially crafted webpage.

Technical detail

CVE-2018-17463 involves improper side effect annotation in V8 that permits escape from sandbox constraints; a remote attacker can craft HTML to trigger unsafe code execution with full process privileges via this annotation bypass.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Google · Chrome
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.