CVE-2016-5198
KEV
🔴 Łataj teraz
Błędne założenia optymalizacji w V8 w Google Chrome umożliwiają zdalne wykonanie kodu.
CVSS
8.8
EPSS
78.7%
Exploit
weaponized
Vendor
google
Opis źródłowy (NVD)
V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading to code execution, via a crafted HTML page.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.8 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 78.7% |
| Opublikowano (NVD) | 2017-01-19 05:59:00 UTC |
| Ostatnia modyfikacja (NVD) | 2026-04-21 17:51:16 UTC |
Referencje
- http://rhn.redhat.com/errata/RHSA-2016-2672.html (chrome-cve-admin@google.com) [Third Party Advisory]
- http://www.securityfocus.com/bid/94079 (chrome-cve-admin@google.com) [Broken Link, Third Party Advisory, VDB Entry]
- http://www.securitytracker.com/id/1037224 (chrome-cve-admin@google.com) [Broken Link, Third Party Advisory, VDB Entry]
- https://chromereleases.googleblog.com/2016/11/stable-channel-update-for-desktop.html (chrome-cve-admin@google.com) [Release Notes, Vendor Advisory]
- https://crbug.com/659475 (chrome-cve-admin@google.com) [Exploit, Issue Tracking]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-5198 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]