CVE-2018-17470: Buffer Overflow
A heap buffer overflow in GPU in Google Chrome prior to 70.0.3538.67 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Other sources
A memory corruption flaw was found in the GPU Internals component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=877874
External References:
https://chromereleases.googleblog.com/2018/10/stable-channel-update-for-desktop.html
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-17470?
CVE-2018-17470 has been assigned a high severity rating due to its potential for sandbox escape and exploitation.
How do I fix CVE-2018-17470?
To fix CVE-2018-17470, update your Google Chrome or Chromium browser to version 70.0.3538.67 or later.
What versions of Chrome are affected by CVE-2018-17470?
CVE-2018-17470 affects versions of Chrome prior to 70.0.3538.67.
Can CVE-2018-17470 lead to remote code execution?
Yes, CVE-2018-17470 can potentially allow a remote attacker to execute code via a crafted HTML page.
Which platforms are vulnerable to CVE-2018-17470?
CVE-2018-17470 impacts multiple platforms including Debian and Red Hat enterprise Linux systems running affected versions of Chrome or Chromium.