ZeroHour

CVE-2018-6065

KEV PoC ×2mass

Integer Overflow in Google Chrome's V8 Engine Allows Remote Heap Corruption

CISA: Google Chromium V8 Integer Overflow Vulnerability

CVSS 3.1
8.8 high
EPSS
60%p99
Published
()
KEV added
AI analysis

CVE-2018-6065 is a high-severity integer overflow (CWE-190) in Google's V8 JavaScript engine that occurs when V8 computes the required allocation size while instantiating a new JavaScript object, causing a miscalculated allocation that can corrupt the heap. A remote attacker triggers the flaw by getting a user to open a crafted HTML page in a vulnerable browser, which is why the CVSS vector includes user interaction (UI:R). Successful exploitation can let the attacker exploit heap corruption, potentially achieving code execution in the browser with high impact to confidentiality, integrity, and availability (CVSS 3.1: 8.8). Google Chrome versions prior to 65.0.3325.146 are affected, along with the Chromium-derived products in the CPE data: Red Hat Enterprise Linux Desktop/Server/Workstation, Debian Linux, and the Mi6 Browser from vendor 'mi'. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-08) with a very high EPSS score (60.3%, 99th percentile) and public proof-of-concept code exists (crbug.com/808192, Exploit-DB 44584), so in-the-wild exploitation should be assumed; no ransomware association is recorded.

What to do: Upgrade Google Chrome/Chromium to version 65.0.3325.146 or later. On Red Hat Enterprise Linux and Debian, install the updated chromium packages per vendor advisories, and apply Mi6 Browser updates supplied by the vendor. Because the flaw is CISA KEV-listed, treat patching as urgent and verify installed browser versions fleet-wide; as an interim mitigation, caution users against following untrusted links, since exploitation requires loading a crafted HTML page.

Affected
google Chrome (Chromium V8 JavaScript engine)all versions prior to 65.0.3325.146
redhat Red Hat Enterprise Linux Desktop (affected via Chromium/V8 shipped with the product)
redhat Red Hat Enterprise Linux Server (affected via Chromium/V8 shipped with the product)
redhat Red Hat Enterprise Linux Workstation (affected via Chromium/V8 shipped with the product)
Debian Linux (affected via Chromium/V8 shipped with the product)
Mi6 Browser (affected via embedded Chromium/V8)
Estimated exposure
masshundreds of millions of users were affected at the 2018 disclosure; plausibly tens of millions of unpatched Chrome/Chromium installs remain worldwide today — Chrome holds roughly two-thirds of global desktop browser usage with an install base in the billions and every build prior to 65.0.3325.146 was vulnerable at disclosure, so even the small unpatched residue seen in public browser-version…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googleredhatdebianmi
Products
chrome, enterprise linux desktop, enterprise linux server, enterprise linux workstation, debian linux, mi6 browser
Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.