EXPOSURES › CVE-2018-17463
CVE-2018-17463
HIGH ⌖ ON CISA KEV · EXPLOITEDA Chromium V8 vulnerability allowed remote code execution via crafted HTML, impacting multiple browsers and potentially DIB organizations using them for web access or internal tools.
CVE-2018-17463 represents a remote code execution vulnerability in the Chromium V8 engine, affecting browsers like Chrome and Edge. DIB organizations relying on these browsers for secure operations face potential compromise if exploited, impacting NIST 800-171 controls related to data protection and system integrity; immediate patching and browser updates are critical.
Shame score — The vulnerability's exploitation in the wild and potential for remote code execution demonstrate a significant security lapse in a widely-used component, highlighting a failure to adequately secure a core browser engine.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 Engine contains an unspecified vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
| PRODUCT | STATUS |
|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) Google |
Authorized |
| Google Workspace Google |
Authorized |