CVE-2018-17463: Google Chromium V8 Remote Code Execution Vulnerability
A remote code execution flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=888923
External References:
https://chromereleases.googleblog.com/2018/10/stable-channel-update-for-desktop.html
Other sources
Google Chromium V8 Engine contains an unspecified vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
— CISA
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/chromium-browserto a version that resolves this vulnerability.Fixed in 70.0.3538.67 - Upgrade
Upgrade
Google Chrometo a version that resolves this vulnerability.Fixed in 70.0.3538.64
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-17463.
What is the title of the vulnerability?
The title of the vulnerability is Google Chromium V8 Remote Code Execution Vulnerability.
What is the severity of CVE-2018-17463?
CVE-2018-17463 has a severity of high with a severity value of 8.8.
How does CVE-2018-17463 allow remote code execution?
CVE-2018-17463 allows remote code execution by exploiting an incorrect side effect annotation in V8 in Google Chrome.
How can I fix CVE-2018-17463?
To fix CVE-2018-17463, update Google Chrome to version 70.0.3538.64 or later.