CVE-2017-15428

HIGH

Google Chrome < 62.0.3202.94 - Out-of-Bounds Write

Title source: rule
STIX 2.1

Description

Insufficient data validation in V8 builtins string generator could lead to out of bounds read and write access in V8 in Google Chrome prior to 62.0.3202.94 and allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

Exploits (1)

nomisec WORKING POC
by w1ldb1t · poc
https://github.com/w1ldb1t/CVE-2017-15428

References (2)

Core 2
Core References
Issue Tracking x_refsource_misc
https://crbug.com/782145

Scores

CVSS v3 8.8
EPSS 0.2721
EPSS Percentile 96.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-125 CWE-787
Status published
Products (1)
google/chrome < 62.0.3202.94
Published Jan 09, 2019
Tracked Since Feb 18, 2026