PT-2018-3406 · Google+3 · Google Chrome+3

Published

2018-11-09

·

Updated

2024-06-15

·

CVE-2018-17478

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Google Chrome versions prior to 70.0.3538.102
Description: The issue is related to incorrect array position calculations in the V8 browser kernel of Google Chrome. This could allow a remote attacker to exploit object corruption via a crafted HTML page, potentially leading to unauthorized access to confidential data, disruption of data integrity, and denial of service.
Recommendations: For versions prior to 70.0.3538.102, update to version 70.0.3538.102 or later to resolve the issue.

Exploit

Fix

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2879
BDU:2020-00778
CVE-2018-17478
DSA-4340-1
OPENSUSE-SU-2018:3835-1
OPENSUSE-SU-2018_3805-1
OPENSUSE-SU-2018_3837-1
OPENSUSE-SU-2024:10681-1
OPENSUSE-SU-2024:12948-1
RHSA-2018:3648
RHSA-2018_3648

Affected Products

Alt Linux
Google Chrome
Red Hat
Suse