Type Confusion Vulnerability in Google Chrome for Multiple Platforms
CVE-2017-5070
Key Information:
- Vendor
- Vendor
- CVE Published:
- 27 October 2017
Badges
Summary
A type confusion vulnerability in V8 within Google Chrome allows a remote attacker to execute arbitrary code within a sandbox environment through a specially crafted HTML page. This flaw affects versions of Chrome prior to 59.0.3071.86 on desktop platforms and 59.0.3071.92 on Android, potentially compromising the integrity of the UI and providing attackers with unauthorized access to system resources.
CISA Reported
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply updates per vendor instructions.
Affected Version(s)
Google Chrome prior to 59.0.3071.86 for Linux, Windows and Mac, and 59.0.3071.92 for Android Google Chrome prior to 59.0.3071.86 for Linux, Windows and Mac, and 59.0.3071.92 for Android
References
EPSS Score
82% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 👾
Exploit known to exist
- 🦅
CISA Reported
Vulnerability published
Vulnerability Reserved