⚠ Actively exploited
Added to CISA KEV on 2022-06-08. Federal agencies required to patch by 2022-06-22. Required action: Apply updates per vendor instructions..

CVE-2018-17463Google Chrome vulnerability

19 documents12 sources
Severity
8.8HIGHNVD
EPSS
92.2%
top 0.29%
CISA KEV
KEV
Added 2022-06-08
Due 2022-06-22
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedNov 14
KEV addedJun 8
KEV dueJun 22
Latest updateDec 5
CISA Required Action: Apply updates per vendor instructions.

Description

Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages5 packages

CVEListV5google/chromeunspecified70.0.3538.64
NVDgoogle/chrome< 70.0.3538.67

Also affects: Debian Linux 9.0

🔴Vulnerability Details

6
GHSA
GHSA-jjm4-89hr-gf27: Incorrect side effect annotation in V8 in Google Chrome prior to 702022-05-13
Project0
JSC Exploits - Project Zero2019-08-01
OSV
CVE-2018-17463: Incorrect side effect annotation in V8 in Google Chrome prior to 702018-11-14
CVEList
CVE-2018-17463: Incorrect side effect annotation in V8 in Google Chrome prior to 702018-11-14
VulnCheck
Google Chromium V8 Remote Code Execution Vulnerability2018

💥Exploits & PoCs

2
Exploit-DB
Google Chrome 67_ 68 and 69 - Object.create Type Confusion (Metasploit)2020-03-09
Metasploit
Google Chrome 67, 68 and 69 Object.create exploit

📋Vendor Advisories

2
CISA
Google Chromium V8 Remote Code Execution Vulnerability2022-06-08
Red Hat
chromium-browser: Remote code execution in V82018-10-16

🕵️Threat Intelligence

5
Trendmicro
MOONSHINE Exploit Kit and DarkNimbus Backdoor Enabling Earth Minotaur’s Multi-Platform Attacks2024-12-05
Trendmicro
MOONSHINE Exploit Kit and DarkNimbus Backdoor Enabling Earth Minotaur’s Multi-Platform Attacks2024-12-05
Trendmicro
MOONSHINE Exploit Kit and DarkNimbus Backdoor Enabling Earth Minotaur’s Multi-Platform Attacks2024-12-05
Trendmicro
MOONSHINE Exploit Kit and DarkNimbus Backdoor Enabling Earth Minotaur’s Multi-Platform Attacks2024-12-05
Trendmicro
MOONSHINE Exploit Kit and DarkNimbus Backdoor Enabling Earth Minotaur’s Multi-Platform Attacks2024-12-05

💬Community

3
Bugzilla
CVE-2018-16435 CVE-2018-17462 CVE-2018-17463 CVE-2018-17464 CVE-2018-17465 CVE-2018-17466 CVE-2018-17467 CVE-2018-17468 CVE-2018-17469 CVE-2018-17470 CVE-2018-17471 CVE-2018-17473 CVE-2018-17474 CVE-22018-10-17
Bugzilla
CVE-2018-16435 CVE-2018-17462 CVE-2018-17463 CVE-2018-17464 CVE-2018-17465 CVE-2018-17466 CVE-2018-17467 CVE-2018-17468 CVE-2018-17469 CVE-2018-17470 CVE-2018-17471 CVE-2018-17473 CVE-2018-17474 CVE-22018-10-17
Bugzilla
CVE-2018-17463 chromium-browser: Remote code execution in V82018-10-17
CVE-2018-17463 — Google Chrome vulnerability | cvebase