CVE-2020-6418

high

Description

Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

From the Tenable Blog

CVE-2020-6418: Google Chrome Type Confusion Vulnerability Exploited in the Wild
CVE-2020-6418: Google Chrome Type Confusion Vulnerability Exploited in the Wild

Published: 2020-02-24

Google is aware of reports that a type confusion flaw in Google Chrome has been exploited in the wild. Background On February 24, Google released a new stable channel update for Google Chrome for Desktop to address several vulnerabilities, including one that has been reportedly exploited in the wild.

References

https://www.trendmicro.com/en_us/research/24/l/earth-minotaur.html

https://thehackernews.com/2024/12/hackers-target-uyghurs-and-tibetans.html

https://www.tenable.com/blog/cve-2021-21148-google-chrome-heap-buffer-overflow-vulnerability-exploited-in-the-wild

https://www.tenable.com/cyber-exposure/2020-threat-landscape-retrospective

https://www.tenable.com/blog/how-covid-19-response-is-expanding-the-cyberattack-surface

https://www.tenable.com/blog/cve-2020-6418-google-chrome-type-confusion-vulnerability-exploited-in-the-wild

https://www.debian.org/security/2020/dsa-4638

https://security.gentoo.org/glsa/202003-08

https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3B5RWJQD5LA45MYLLR55KZJOJ5NVZGP/

https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6IOHSO6BUKC6I66J5PZOMAGFVJ66ZS57/

https://crbug.com/1053604

https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_24.html

https://access.redhat.com/errata/RHSA-2020:0738

http://packetstormsecurity.com/files/156632/Google-Chrome-80-JSCreate-Side-Effect-Type-Confusion.html

Details

Source: Mitre, NVD

Published: 2020-02-27

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High