Skip to content
COOEY

EXPOSURES › CVE-2018-17463

CVE-2018-17463

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-06-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-17463 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

A Chromium V8 vulnerability allowed remote code execution via crafted HTML, impacting multiple browsers and potentially DIB organizations using them for web access or internal tools.

CVE-2018-17463 represents a remote code execution vulnerability in the Chromium V8 engine, affecting browsers like Chrome and Edge. DIB organizations relying on these browsers for secure operations face potential compromise if exploited, impacting NIST 800-171 controls related to data protection and system integrity; immediate patching and browser updates are critical.

Shame score — The vulnerability's exploitation in the wild and potential for remote code execution demonstrate a significant security lapse in a widely-used component, highlighting a failure to adequately secure a core browser engine.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium V8 Engine contains an unspecified vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized