Loading
Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Use CWE-787, Google vendor hub and Chrome product page to widen CVE-2018-17480 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-6920, CVE-2026-6919 and CVE-2026-6363 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 27th, 2026.