vendor:
Google Chrome
by:
Bogdan Kurinnoy
7.5
CVSS
HIGH
Out-of-memory Denial of Service
400
CWE
Product Name: Google Chrome
Affected Version From: Google Chrome 71.0.3578.98
Affected Version To: Google Chrome 71.0.3578.98
Patch Exists: YES
Related CWE: N/A
CPE: a:google:chrome
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows x64
2018
Google Chrome 71.0.3578.98 V8 JavaScript Engine – Out-of-memory. Denial of Service (PoC)
A fatal javascript Out-of-Memory (OOM) vulnerability exists in the CALL_AND_RETRY_LAST function of the V8 JavaScript Engine in Google Chrome 71.0.3578.98. An attacker can exploit this vulnerability to cause a denial of service condition. This vulnerability is tracked in Chromium as issue 917631.
Mitigation:
Upgrade to the latest version of Google Chrome.