vendor:
V8 JavaScript Engine
by:
Unknown
7.5
CVSS
HIGH
Out-of-Bounds Write
119
CWE
Product Name: V8 JavaScript Engine
Affected Version From: Not specified
Affected Version To: Not specified
Patch Exists: YES
Related CWE: Not available
CPE: cpe:2.3:a:google:v8:*:*:*:*:*:*:*
Platforms Tested: Not specified
2017
V8 Out-of-Bounds Write Exploit
This exploit targets a vulnerability in the V8 JavaScript engine, specifically an out-of-bounds write bug. By manipulating certain arrays and memory layouts, the exploit is able to write to memory locations outside of the intended bounds, potentially leading to arbitrary code execution. The exploit takes advantage of a bug reported in the Chromium bug tracker (https://crbug.com/716044).
Mitigation:
The vulnerability was fixed in a patch by the V8 team. Users are advised to update to the latest version of V8 to mitigate this issue.