KLA11249
Multiple vulnerabilities in Google Chrome
Обновлено: 05/07/2018
CVSS
10.0
Дата обнаружения
10/05/2018
Уровень угрозы
Critical
Описание

Multiple serious vulnerabilities have been found in Google Chrome. Malicious users can exploit these vulnerabilities to execute arbitrary code, cause denial of service and gain privileges.

Below is a complete list of vulnerabilities:

  1. A chain leading to sandbox escape can be exploited remotely to execute arbitrary code;
  2. A privilege escalation vulnerability in extensions can be exploited remotely to gain privileges;
  3. A type confusion vulnerability in V8 can be exploited remotely possibly to execute arbitrary code;
  4. A heap buffer overflow vulnerability in PDFium can be exploited remotely possibly to cause denial of service;

NB: This vulnerability does not have any public CVSS rating, so rating can be changed by the time.

NB: At this moment Google has just reserved CVE numbers for these vulnerabilities. Information can be changed soon.

Пораженные продукты

Google Chrome earlier than 66.0.3359.170

Решение

Update to latest version.
Download Google Chrome

Первичный источник обнаружения
Stable Channel Update for Desktop
Оказываемое влияние
?
ACE 
[?]

PE 
[?]

DoS 
[?]
Связанные продукты
Google Chrome
CVE-IDS

CVE-2018-6122
CVE-2018-6121
CVE-2018-6120