CVE-2018-17463: high-severity vulnerability in Google Chrome
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
A flaw in Chrome's V8 JavaScript engine incorrectly marked certain operations as safe, allowing attackers to run malicious code within the browser's sandbox through a specially crafted webpage.
CVE-2018-17463 involves improper side effect annotation in V8 that permits escape from sandbox constraints; a remote attacker can craft HTML to trigger unsafe code execution with full process privileges via this annotation bypass.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.