CVE-2018-17480 is a critical vulnerability in Google Chrome's V8 JavaScript engine, affecting versions prior to 71.0.3578.80, as well as Debian and Red Hat distributions. It allows a remote attacker to execute arbitrary code within the browser's sandbox by tricking a user into visiting a specially crafted HTML page. This high-severity flaw (CVSS 8.8) has a high potential for impact on confidentiality, integrity, and availability, and is actively exploited in the wild, as indicated by its presence in the KEV catalog and high EPSS score. Despite active exploitation, no public exploit modules like Metasploit or ExploitDB are currently available, though it has garnered significant community discussion and media coverage, including reports of its use by the POISON CARP threat actor.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 71.0.3578.80CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.