CVE-2018-8381 is a remote code execution vulnerability within the Chakra scripting engine, affecting Microsoft Edge and ChakraCore, stemming from how these products handle objects in memory. This vulnerability carries a CVSS score of 7.5 (High), indicating a high potential for impact (confidentiality, integrity, availability) if successfully exploited, though it requires user interaction and has high attack complexity. While it has garnered some community discussion and media coverage, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on the CISA KEV catalog as actively exploited. Its EPSS score suggests a relatively low likelihood of exploitation compared to most CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.10.1CPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.