CVE-2018-18359: High severity google chrome vulnerability
An out of bounds read flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=907714
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
Other sources
Incorrect handling of Reflect.construct in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-18359?
CVE-2018-18359 is a vulnerability that allowed a remote attacker to perform an out of bounds memory read in Google Chrome prior to version 71.0.3578.80.
How can this vulnerability be exploited?
This vulnerability can be exploited by an attacker through a crafted HTML page.
What is the severity of CVE-2018-18359?
The severity of CVE-2018-18359 is high with a severity value of 8.8.
Which software versions are affected by CVE-2018-18359?
Google Chrome versions prior to 71.0.3578.80, Redhat Linux Desktop 6.0, Redhat Linux Server 6.0, Redhat Linux Workstation 6.0, and Debian Debian Linux 9.0 are affected.
How do I fix CVE-2018-18359?
To fix CVE-2018-18359, update to Google Chrome version 71.0.3578.80 or later, or apply the appropriate patch provided by Redhat or Debian for their affected Linux distributions.