Junglewise Threat Intelligence

CVE-2018-6065: Google Chromium V8 Integer Overflow Vulnerability

CVE-2018-6065 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-06-08

Technologies: Google Chrome, Google Chromium V8, Microsoft Edge, Opera Software Opera. Vendors: Google, Microsoft, Opera Software.

Executive brief

An integer overflow vulnerability exists in the Google Chromium V8 engine when computing the required allocation size for new JavaScript objects. A remote attacker can exploit this via a crafted HTML page to cause heap corruption, potentially leading to arbitrary code execution.

Affected products

  • Google Chrome prior to 65.0.3325.146
  • Google V8 Engine
  • Microsoft Edge
  • Opera Software Opera

Timeline

  • 2018-03-06: patched: Stable Channel Update for Desktop (65.0.3325.146) released.
  • 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-06-08: disclosed: NVD publication date.
  • 2022-06-08: exploited: Confirmed as exploited in the wild per CISA KEV.

Related threats