CVE-2018-8298: ChakraCore Scripting Engine Type Confusion Vulnerability
High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2022-03-03. EPSS: 74.7% chance of exploitation in the next 30 days.
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CVE-2018-8287, CVE-2018-8288, CVE-2018-8291, CVE-2018-8296.
Affected products
- Microsoft ChakraCore: before 1.10.1 (fixed in 1.10.1)
Published 2018-07-11. Last modified 2026-06-17.