CVE-2008-6998

Google Chrome < 0.2.149.29 - Stack-Based Buffer Overflow via Hover Over Long Path Link

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6998. PoCs published by Shinnok.

AI-analyzed exploit summary This exploit demonstrates a denial-of-service vulnerability in Google Chrome 0.2.149.27 by using an excessively long URL path with repeated '/crash/' segments, causing the browser to crash when hovered or clicked.

Description

Stack-based buffer overflow in chrome/common/gfx/url_elider.cc in Google Chrome 0.2.149.27 and other versions before 0.2.149.29 might allow user-assisted remote attackers to execute arbitrary code via a link target (href attribute) with a large number of path elements, which triggers the overflow when the status bar is updated after the user hovers over the link.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Shinnok · htmldoswindows
https://www.exploit-db.com/exploits/6372

This exploit demonstrates a denial-of-service vulnerability in Google Chrome 0.2.149.27 by using an excessively long URL path with repeated '/crash/' segments, causing the browser to crash when hovered or clicked.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Google Chrome 0.2.149.27
No auth needed
Prerequisites: Victim must visit the malicious webpage or interact with the crafted link
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/44934
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45032
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31034
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6372
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/48264
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31071

Scores

EPSS 0.0968
EPSS Percentile 94.9%

Details

CWE
CWE-119
Status published
Products (1)
google/chrome 0.2.149.27
Published Aug 19, 2009
Tracked Since Feb 18, 2026