CVE-2018-17462: Use After Free
A sandbox escape flaw was found in the AppCache component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=888926
External References:
https://chromereleases.googleblog.com/2018/10/stable-channel-update-for-desktop.html
Other sources
Incorrect refcounting in AppCache in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform a sandbox escape via a crafted HTML page.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2018-17462?
The severity of CVE-2018-17462 is critical, with a severity score of 9.6.
What software versions are affected by CVE-2018-17462?
Google Chrome versions prior to 70.0.3538.67 and Redhat Linux Desktop, Server, and Workstation versions 6.0 are affected by CVE-2018-17462.
How can a remote attacker exploit CVE-2018-17462?
A remote attacker can exploit CVE-2018-17462 by using a crafted HTML page to perform a sandbox escape in Google Chrome.
What is the remedy for CVE-2018-17462?
The remedy for CVE-2018-17462 is to update Google Chrome to version 70.0.3538.67 or later.
Where can I find more information about CVE-2018-17462?
You can find more information about CVE-2018-17462 at the following references: [LINK_1], [LINK_2], [LINK_3].