CVE-2016-5198: Google Chromium V8 Out-of-Bounds Memory Vulnerability
High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2022-06-08. EPSS: 34.2% chance of exploitation in the next 30 days.
V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading to code execution, via a crafted HTML page.
Affected products
- Google Chrome: before 54.0.2840.90 (fixed in 54.0.2840.90); before 54.0.2840.85 (fixed in 54.0.2840.85); before 54.0.2840.87 (fixed in 54.0.2840.87)
- Red Hat Enterprise Linux Desktop: version 6.0 only
- Red Hat Enterprise Linux Server: version 6.0 only
- Red Hat Enterprise Linux Workstation: version 6.0 only
Published 2017-01-19. Last modified 2026-06-17.