Multiple vulnerabilities in Google Chrome

Обновлено: 03/06/2020
Дата обнаружения
Уровень угрозы

Multiple serious vulnerabilities have been found in Google Chrome. Malicious users can exploit these vulnerabilities to execute arbitrary code, cause denial of service and gain privileges.

Below is a complete list of vulnerabilities:

  1. A chain leading to sandbox escape can be exploited remotely to execute arbitrary code;
  2. A privilege escalation vulnerability in extensions can be exploited remotely to gain privileges;
  3. A type confusion vulnerability in V8 can be exploited remotely possibly to execute arbitrary code;
  4. A heap buffer overflow vulnerability in PDFium can be exploited remotely possibly to cause denial of service;

NB: This vulnerability does not have any public CVSS rating, so rating can be changed by the time.

NB: At this moment Google has just reserved CVE numbers for these vulnerabilities. Information can be changed soon.

Пораженные продукты

Google Chrome earlier than 66.0.3359.170


Update to latest version.
Download Google Chrome

Первичный источник обнаружения
Stable Channel Update for Desktop
Оказываемое влияние

Связанные продукты
Google Chrome
Узнай статистику распространения уязвимостей в твоем регионе