← Vulnerability feed

Vulnerability record · CVE-2017-5070 · published 27 October 2017

CVE-2017-5070: Google Chrome V8 type confusion allows sandboxed code execution

Google · Chrome

Google Chrome's V8 JavaScript engine contained a type confusion flaw (CWE-843) in versions prior to 59.0.3071.86 on Linux, Windows and Mac, and 59.0.3071.92 on Android. A remote attacker could trigger it with a crafted HTML page, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog, so it has been used in real attacks.

8.8 CVSS 3.1 High CISA KEV since 8 Jun 2022 EPSS 32% · top 1.7% CWE-843 · Type confusion
8.8CVSS 3.1 base score, v2 6.8
32%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
13References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityIt is in CISA KEV with a high EPSS percentile and public exploit reference, but exploitation requires user interaction and the affected versions are long superseded.

What it is

Google Chrome's V8 JavaScript engine contained a type confusion flaw (CWE-843) in versions prior to 59.0.3071.86 on Linux, Windows and Mac, and 59.0.3071.92 on Android. A remote attacker could trigger it with a crafted HTML page, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog, so it has been used in real attacks.

Impact

An attacker can execute arbitrary code inside the browser sandbox, which combined with a sandbox escape would give full code execution on the host. The CVSS 3.1 score is 8.8 (HIGH) with high confidentiality, integrity and availability impact.

Attack surface

Reached over the network by a victim loading a crafted HTML page in Chrome; the vector is AV:N/AC:L/PR:N/UI:R, so no authentication is needed but user interaction (opening the page) is required.

Exploitation

CISA added it to KEV on 2022-06-08 with a 2022-06-22 remediation due date, and EPSS gives a 30-day probability of 0.31212 (98th percentile); a reference is tagged Exploit, indicating public exploit material exists. No ransomware campaign use is documented.

What to do

  • Update Chrome to 59.0.3071.86 or later (59.0.3071.92 on Android); apply the referenced Red Hat and Gentoo errata for packaged Chromium builds.
  • Enforce automatic browser updates and verify installed versions across endpoints, including Android devices.
  • Restrict or isolate browsing of untrusted web content, and keep the browser sandbox enabled.
  • Track KEV remediation deadlines and confirm closure of CVE-2017-5070 on all affected systems.

Detection

  • Hunt for Chrome or Chromium processes spawning unexpected child processes or writing executables to temp directories.
  • Monitor for crashes or abnormal V8/type-confusion-related browser crash reports on endpoints.
  • Alert on network fetches of pages from hosts associated with known exploit kits or malicious ads.
  • Audit endpoint inventories for Chrome versions below 59.0.3071.86/59.0.3071.92.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-5070 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Google Chromium V8 Type Confusion Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-5070 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-10585Google Chrome V8 type confusion enables heap corruptionChrome's V8 JavaScript engine contains a type confusion flaw (CWE-843) that can lead to heap corruption when processing a crafted HTML page. It affec…KEVEPSS 5.4%analysed9.8CVE-2019-5544OpenSLP heap out-of-bounds write in VMware ESXi and Horizon DaaSOpenSLP as shipped in VMware ESXi and Horizon DaaS contains a heap overwrite (out-of-bounds write) flaw. VMware rates it Critical with a maximum CVSS…KEVEPSS 97%analysed9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed9.8CVE-2016-4171Adobe Flash Player unspecified remote code execution flawCVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code thr…KEVEPSS 20%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2015-2590Oracle Java SE Libraries flaw allows remote code executionCVE-2015-2590 is an unspecified vulnerability in the Libraries component of Oracle Java SE 6u95, 7u80, 8u45 and Java SE Embedded 7u75, 8u33. The reco…KEVEPSS 25%analysed9.8CVE-2015-5123Adobe Flash Player ActionScript 3 BitmapData use-after-freeAdobe Flash Player contains a use-after-free in the ActionScript 3 BitmapData class, triggered by crafted Flash content that overrides a valueOf func…KEVEPSS 19%analysed

Source: NIST National Vulnerability Database (record CVE-2017-5070), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.