CVE-2018-18342 PUBLISHED

Execution of user supplied Javascript during object deserialization can update object length leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

EPSS 1.89% · 83.1th percentile

Risk Scores

EPSS Score
1.89%
83.1th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSchromium-browser0, 61.0.3163.100-0ubuntu1.1378, 62.0.3202.62-0ubuntu0.17.10.1380
Ubuntu:16.04:LTSchromium-browser60.0.3112.78-0ubuntu0.16.04.1293, 60.0.3112.113-0ubuntu0.16.04.1298, 61.0.3163.79-0ubuntu0.16.04.1300

Timeline

References

Open in Interactive Console →