EXPOSURES › CVE-2018-17480
CVE-2018-17480
HIGH ⌖ ON CISA KEV · EXPLOITEDA Chromium V8 out-of-bounds write vulnerability allowed remote code execution via crafted HTML, impacting multiple browsers including Chrome and Edge, and is currently being exploited in the wild.
This vulnerability in the Chromium V8 engine enables remote code execution within a sandbox, affecting numerous browsers and posing a significant risk to DIB organizations reliant on these platforms. Failure to promptly patch exposes systems to potential compromise and impacts NIST 800-171 compliance requirements related to vulnerability management. Immediate patching and browser updates are critical.
Shame score — The vulnerability's active exploitation and potential for widespread impact, despite being a known issue, demonstrates a concerning lack of proactive security measures.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
| PRODUCT | STATUS |
|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) Google |
Authorized |
| Google Workspace Google |
Authorized |