⚠ Actively exploited
Added to CISA KEV on 2022-06-08. Federal agencies required to patch by 2022-06-22. Required action: Apply updates per vendor instructions..

CVE-2017-5030Out-of-bounds Read in Google Chrome

CWE-125Out-of-bounds Read17 documents10 sources
Severity
8.8HIGHNVD
EPSS
50.7%
top 2.14%
CISA KEV
KEV
Added 2022-06-08
Due 2022-06-22
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedApr 24
KEV addedJun 8
KEV dueJun 22
Latest updateDec 5
CISA Required Action: Apply updates per vendor instructions.

Description

Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a remote attacker to execute arbitrary code via a crafted HTML page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

Also affects: Debian Linux 8.0, 9.0

🔴Vulnerability Details

4
GHSA
GHSA-6w47-3vvr-m9hm: Incorrect handling of complex species in V8 in Google Chrome prior to 572022-04-30
OSV
oxide-qt vulnerabilities2017-03-29
OSV
CVE-2017-5030: Incorrect handling of complex species in V8 in Google Chrome prior to 572017-03-10
VulnCheck
Google Chromium V8 Memory Corruption Vulnerability2017

📋Vendor Advisories

3
CISA
Google Chromium V8 Memory Corruption Vulnerability2022-06-08
Ubuntu
Oxide vulnerabilities2017-03-29
Red Hat
chromium-browser: memory corruption in v82017-03-09

🕵️Threat Intelligence

5
Trendmicro
MOONSHINE Exploit Kit and DarkNimbus Backdoor Enabling Earth Minotaur’s Multi-Platform Attacks2024-12-05
Trendmicro
MOONSHINE Exploit Kit and DarkNimbus Backdoor Enabling Earth Minotaur’s Multi-Platform Attacks2024-12-05
Trendmicro
MOONSHINE Exploit Kit and DarkNimbus Backdoor Enabling Earth Minotaur’s Multi-Platform Attacks2024-12-05
Trendmicro
MOONSHINE Exploit Kit and DarkNimbus Backdoor Enabling Earth Minotaur’s Multi-Platform Attacks2024-12-05
Trendmicro
MOONSHINE Exploit Kit and DarkNimbus Backdoor Enabling Earth Minotaur’s Multi-Platform Attacks2024-12-05

📄Research Papers

2
arXiv
SOK: On the Analysis of Web Browser Security2021-12-31
arXiv
Rethinking Misalignment to Raise the Bar for Heap Pointer Corruption2018-08-08

💬Community

2
Bugzilla
chromium: various flaws [fedora-all]2017-03-10
Bugzilla
CVE-2017-5030 chromium-browser: memory corruption in v82017-03-10