⚠ Actively exploited
Added to CISA KEV on 2022-06-08. Federal agencies required to patch by 2022-06-22. Required action: Apply updates per vendor instructions..
CVE-2017-5030 — Out-of-bounds Read in Google Chrome
Severity
8.8HIGHNVD
EPSS
50.7%
top 2.14%
CISA KEV
KEV
Added 2022-06-08
Due 2022-06-22
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedApr 24
KEV addedJun 8
KEV dueJun 22
Latest updateDec 5
CISA Required Action: Apply updates per vendor instructions.
Description
Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a remote attacker to execute arbitrary code via a crafted HTML page.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages4 packages
Also affects: Debian Linux 8.0, 9.0
🔴Vulnerability Details
4GHSA▶
GHSA-6w47-3vvr-m9hm: Incorrect handling of complex species in V8 in Google Chrome prior to 57↗2022-04-30
OSV
▶
📋Vendor Advisories
3🕵️Threat Intelligence
5Trendmicro▶
MOONSHINE Exploit Kit and DarkNimbus Backdoor Enabling Earth Minotaur’s Multi-Platform Attacks↗2024-12-05
Trendmicro▶
MOONSHINE Exploit Kit and DarkNimbus Backdoor Enabling Earth Minotaur’s Multi-Platform Attacks↗2024-12-05
Trendmicro▶
MOONSHINE Exploit Kit and DarkNimbus Backdoor Enabling Earth Minotaur’s Multi-Platform Attacks↗2024-12-05
Trendmicro▶
MOONSHINE Exploit Kit and DarkNimbus Backdoor Enabling Earth Minotaur’s Multi-Platform Attacks↗2024-12-05
Trendmicro▶
MOONSHINE Exploit Kit and DarkNimbus Backdoor Enabling Earth Minotaur’s Multi-Platform Attacks↗2024-12-05