### [CVE-2018-17463](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17463) ![](https://img.shields.io/static/v1?label=Product&message=Chrome&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=%3C%2070.0.3538.64%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Inappropriate%20implementation&color=brighgreen) ### Description Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. ### POC #### Reference - http://packetstormsecurity.com/files/156640/Google-Chrome-67-68-69-Object.create-Type-Confusion.html - http://packetstormsecurity.com/files/156640/Google-Chrome-67-68-69-Object.create-Type-Confusion.html #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/Ostorlab/KEV - https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors - https://github.com/Uniguri/CVE-1day - https://github.com/changelog2020/JSEChalls - https://github.com/ernestang98/win-exploits - https://github.com/hwiwonl/dayone - https://github.com/jhalon/CVE-2018-17463 - https://github.com/kdmarti2/CVE-2018-17463 - https://github.com/rycbar77/V8Exploits - https://github.com/tunz/js-vuln-db - https://github.com/w0lfzhang/browser_pwn_learning