Vulnerability record · CVE-2017-5070 · published 27 October 2017
CVE-2017-5070: Google Chrome V8 type confusion allows sandboxed code execution
Google · Chrome
Google Chrome's V8 JavaScript engine contained a type confusion flaw (CWE-843) in versions prior to 59.0.3071.86 on Linux, Windows and Mac, and 59.0.3071.92 on Android. A remote attacker could trigger it with a crafted HTML page, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog, so it has been used in real attacks.
Description
Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with a high EPSS percentile and public exploit reference, but exploitation requires user interaction and the affected versions are long superseded.
What it is
Google Chrome's V8 JavaScript engine contained a type confusion flaw (CWE-843) in versions prior to 59.0.3071.86 on Linux, Windows and Mac, and 59.0.3071.92 on Android. A remote attacker could trigger it with a crafted HTML page, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog, so it has been used in real attacks.
Impact
An attacker can execute arbitrary code inside the browser sandbox, which combined with a sandbox escape would give full code execution on the host. The CVSS 3.1 score is 8.8 (HIGH) with high confidentiality, integrity and availability impact.
Attack surface
Reached over the network by a victim loading a crafted HTML page in Chrome; the vector is AV:N/AC:L/PR:N/UI:R, so no authentication is needed but user interaction (opening the page) is required.
Exploitation
CISA added it to KEV on 2022-06-08 with a 2022-06-22 remediation due date, and EPSS gives a 30-day probability of 0.31212 (98th percentile); a reference is tagged Exploit, indicating public exploit material exists. No ransomware campaign use is documented.
What to do
- Update Chrome to 59.0.3071.86 or later (59.0.3071.92 on Android); apply the referenced Red Hat and Gentoo errata for packaged Chromium builds.
- Enforce automatic browser updates and verify installed versions across endpoints, including Android devices.
- Restrict or isolate browsing of untrusted web content, and keep the browser sandbox enabled.
- Track KEV remediation deadlines and confirm closure of CVE-2017-5070 on all affected systems.
Detection
- Hunt for Chrome or Chromium processes spawning unexpected child processes or writing executables to temp directories.
- Monitor for crashes or abnormal V8/type-confusion-related browser crash reports on endpoints.
- Alert on network fetches of pages from hosts associated with known exploit kits or malicious ads.
- Audit endpoint inventories for Chrome versions below 59.0.3071.86/59.0.3071.92.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-5070 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Google Chromium V8 Type Confusion Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-5070 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-5070), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.