CVE-2017-5030: Google Chromium V8 Memory Corruption Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2022-06-08. EPSS: 40.6% chance of exploitation in the next 30 days.

Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a remote attacker to execute arbitrary code via a crafted HTML page.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Google Chrome: before 57.0.2987.98 (fixed in 57.0.2987.98); before 57.0.2987.108 (fixed in 57.0.2987.108)
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only

Published 2017-04-24. Last modified 2026-06-17.