Junglewise Threat Intelligence

CVE-2020-6418: Google Chromium V8 Type Confusion Vulnerability

CVE-2020-6418 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Google Chromium V8, Google Chrome, Microsoft Edge, Opera Software Opera. Vendors: Google, Microsoft, Opera Software.

Executive brief

A type confusion vulnerability exists in the Google Chromium V8 engine that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. The flaw is triggered when the engine incorrectly handles object types, leading to memory safety issues.

Affected products

  • Google Chrome prior to 80.0.3987.122
  • Google V8 Engine prior to 80.0.3987.122
  • Microsoft Edge
  • Opera Software Opera

Timeline

  • 2020-02-24: patched: Stable channel update for desktop (80.0.3987.122) released.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: disclosed: Publicly disclosed/published date.
  • exploited: Reported as exploited in the wild.

Related threats