Skip to main content

CVE-2017-15428

Description

Insufficient data validation in V8 builtins string generator could lead to out of bounds read and write access in V8 in Google Chrome prior to 62.0.3202.94 and allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

nvd
CVE ID: CVE-2017-15428
Base Score: 8.8
Base Severity: HIGH
Vector String:CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Proof Of Concept

w1ldb1t

An exploit for CVE-2017-15428.

Refrence: GitHub

Refrence: NVD