LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-17480: Google Chromium V8 Out-of-Bounds Write Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 8, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 22, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-17480 to its Known Exploited Vulnerabilities catalog on Jun 8, 2022, with a federal patch deadline of Jun 22, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple…

CVE-2018-17480 is an out-of-bounds write vulnerability in the Google Chromium V8 JavaScript engine. A remote attacker can use a crafted HTML page to execute code inside the browser sandbox. Because V8 powers multiple Chromium-based browsers—including Google Chrome, Microsoft Edge, and Opera—the issue can affect a wide range of desktop and managed endpoints. Defenders should treat it as a high-priority browser engine flaw and confirm exact impact and fixes against the vendor advisory.

How it works

The weakness is classified as CWE-787 (out-of-bounds write). In an out-of-bounds write, the engine writes data past the bounds of an allocated buffer. When this occurs inside V8 while processing JavaScript or related page content, memory corruption can result. An attacker who can lure a user to a malicious page supplies crafted HTML that triggers the flawed code path. Successful exploitation allows code execution within the browser’s sandbox. Public detail on the precise trigger and memory layout is limited; treat any exploit description outside the vendor advisory as unverified. The attack requires the victim to render the malicious page in a vulnerable Chromium-based browser; no additional local privileges are described in the available summary.

Am I affected? How to find it in your systems

Chromium V8 is embedded in Google Chrome, Microsoft Edge (Chromium-based), Opera, and other browsers or embedded WebView components that ship the same engine. It commonly appears on user workstations, VDI images, kiosks, and any application that bundles a Chromium renderer.

Only versions listed as vulnerable in the official advisory should be treated as affected; do not assume ranges without confirmation.

How to remediate

Apply the vendor-supplied updates that address CVE-2018-17480 as the primary fix. CISA directs organizations to apply updates per vendor instructions. Deploy the patched browser or component builds through your standard software-deployment pipeline, then verify installation on a sample of endpoints.

Hardening that reduces exposure for this class of flaw includes keeping browsers on the stable auto-update channel, removing unneeded secondary browsers, and enforcing least-privilege user accounts so that sandbox escape impact is limited.

If you can't patch immediately

When immediate patching is not possible, reduce risk with compensating controls while you schedule the update.

These measures do not eliminate the vulnerability; they only lower likelihood and impact until the vendor update is installed.

If your data may have been exposed

Actively exploited browser engine vulnerabilities can lead to endpoint compromise and subsequent data theft. Ransomware use of this specific CVE is not documented. If you suspect exploitation, follow your incident-response process: isolate affected hosts, preserve memory and disk evidence, and hunt for persistence or lateral movement. As a further check, you can run a free exposure scan of your email addresses against known breach data sets to see whether credentials or personal data have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGoogle · Chromium V8
WeaknessCWE-787
Added to CISA KEVJun 8, 2022
Federal patch deadlineJun 22, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities