CVE-2018-17480: Google Chromium V8 Out-of-Bounds Write Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2022-06-08. EPSS: 35.6% chance of exploitation in the next 30 days.

Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Google Chrome: before 71.0.3578.80 (fixed in 71.0.3578.80)
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only

Published 2018-12-11. Last modified 2026-06-17.