Executive brief
A type confusion vulnerability exists in the Google Chromium V8 engine that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. The flaw is triggered when the engine incorrectly handles object types, leading to memory safety issues.
Affected products
- Google Chrome prior to 80.0.3987.122
- Google V8 Engine prior to 80.0.3987.122
- Microsoft Edge
- Opera Software Opera
Timeline
- 2020-02-24: patched: Stable channel update for desktop (80.0.3987.122) released.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2021-11-03: disclosed: Publicly disclosed/published date.
- exploited: Reported as exploited in the wild.