KLA11249
Multiple vulnerabilities in Google Chrome
Updated: 07/05/2018
CVSS
?
10.0
Detect date
?
05/10/2018
Severity
?
Critical
Description

Multiple serious vulnerabilities have been found in Google Chrome. Malicious users can exploit these vulnerabilities to execute arbitrary code, cause denial of service and gain privileges.

Below is a complete list of vulnerabilities:

  1. A chain leading to sandbox escape can be exploited remotely to execute arbitrary code;
  2. A privilege escalation vulnerability in extensions can be exploited remotely to gain privileges;
  3. A type confusion vulnerability in V8 can be exploited remotely possibly to execute arbitrary code;
  4. A heap buffer overflow vulnerability in PDFium can be exploited remotely possibly to cause denial of service;

NB: This vulnerability does not have any public CVSS rating, so rating can be changed by the time.

NB: At this moment Google has just reserved CVE numbers for these vulnerabilities. Information can be changed soon.

Affected products

Google Chrome earlier than 66.0.3359.170

Solution

Update to latest version.
Download Google Chrome

Original advisories

Stable Channel Update for Desktop

Impacts
?
ACE 
[?]

PE 
[?]

DoS 
[?]
Related products
Google Chrome
CVE-IDS
?

CVE-2018-6122
CVE-2018-6121
CVE-2018-6120