CVE-2018-8276 is a security feature bypass vulnerability in the Microsoft Chakra scripting engine, affecting Microsoft Edge and ChakraCore. This flaw allows an attacker to bypass Control Flow Guard (CFG), potentially leading to a denial of service or information disclosure. With a CVSS score of 6.5 (Medium), it requires user interaction (UI:R) and network access (AV:N) but has low attack complexity (AC:L), primarily impacting integrity (I:H). While it has a high FAUCET Risk Score of 75/100, there is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog. Community discussion and media coverage are minimal, with only one mention and one article found.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.