ZERO
Back
vulnerabilityThe Hacker News - V8 Sandbox

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

The BlueMoon exploit kit chained an additional V8 sandbox escape in Google Chrome after exploiting the V8 type-confusion flaw. The sandbox escape had no assigned CVE identifier and was used in the wild as part of an exploit chain operated by multiple espionage-motivated activity clusters.

Exploitation evidence
Has exploited

Affected software

CVSS (Common Vulnerability Scoring System)

Preferred assessment

Vector

Attack vector

Attack complexity

Privileges required

User interaction

Scope

Confidentiality impact

Integrity impact

Availability impact

Source assessments

EPSS (Exploit Prediction Scoring System)

Probability

Percentile

Model

Preferred remediation

Action