Vulnerability record · CVE-2017-5030 · published 24 April 2017
CVE-2017-5030: Google Chrome V8 out-of-bounds read allows remote code execution
Google · Chrome
Google Chrome's V8 JavaScript engine mishandled complex species, producing an out-of-bounds read (CWE-125) that can be turned into memory corruption. A remote attacker can trigger it with a crafted HTML page, and because Chrome is widely deployed, unpatched browsers are a broad target.
Description
Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a remote attacker to execute arbitrary code via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with a high EPSS score and enables remote code execution, though exploitation requires user interaction and the flaw is long patched.
What it is
Google Chrome's V8 JavaScript engine mishandled complex species, producing an out-of-bounds read (CWE-125) that can be turned into memory corruption. A remote attacker can trigger it with a crafted HTML page, and because Chrome is widely deployed, unpatched browsers are a broad target.
Impact
Successful exploitation lets an attacker execute arbitrary code in the browser process context, giving full compromise of confidentiality, integrity and availability on the victim's machine.
Attack surface
Reached over the network by loading a crafted HTML page in Chrome; no authentication is required but the victim must interact with the page (UI:R). The CVSS vector is AV:N/AC:L/PR:N/UI:R/S:U.
Exploitation
CVE-2017-5030 is listed in CISA KEV (added 2022-06-08), and EPSS gives a 30-day probability of 0.41691 (98.6th percentile), indicating observed exploitation and elevated risk. A reference is tagged Exploit, but no public exploit details are provided in this record.
What to do
- Update Chrome to 57.0.2987.98 or later on Linux, Windows and Mac, and 57.0.2987.108 or later on Android, per the vendor release notes.
- Apply the corresponding Debian DSA-3810, Red Hat RHSA-2017-0499 and Gentoo GLSA-201704-02 updates for packaged Chromium/Chrome builds.
- Enforce automatic browser updates and verify version compliance across endpoints.
- Restrict or sandbox browser use for high-risk users and block untrusted web content where feasible.
Detection
- Monitor for Chrome/Chromium versions below the fixed builds using endpoint software inventory.
- Hunt for browser crashes or renderer process terminations consistent with V8 memory corruption.
- Review proxy and DNS logs for access to known exploit-hosting or malicious pages tied to this CVE.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-5030 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Google Chromium V8 Memory Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-5030 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-5030), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.