ZeroHour

CVE-2020-6418

KEV PoC ×2mass

Type Confusion in Google Chrome's V8 Engine Enables Heap Corruption

CISA: Google Chromium V8 Type Confusion Vulnerability

CVSS 3.1
8.8 high
EPSS
79%p100
Published
()
KEV added
AI analysis

CVE-2020-6418 is a type confusion vulnerability (CWE-843) in V8, the JavaScript engine used in Google Chrome and Chromium, affecting versions prior to 80.0.3987.122. A remote attacker triggers it by persuading a user to open a crafted HTML page whose JavaScript causes V8 to mishandle object types (public PoCs reference a JSCreate side-effect issue), potentially leading to heap corruption. Successful exploitation can yield arbitrary code execution in the browser, a common stepping stone for further compromise on the victim's system. Any Chrome/Chromium deployment with the vulnerable V8 was affected, including Chromium packages shipped by Fedora, Red Hat Enterprise Linux, and Debian. The flaw was a zero-day exploited in the wild when patched in February 2020; it is listed in CISA KEV (added 2021-11-03) and carries a very high EPSS of 78.8%, making it a priority patch.

What to do: Update Google Chrome to 80.0.3987.122 or later and confirm the running version via chrome://settings/help or chrome://version. Apply the updated Chromium packages from Fedora, Red Hat, and Debian on managed Linux endpoints and check whether any hosts still run pre-fix Chromium. Given the KEV listing and 78.8% EPSS, treat patching as urgent; as an interim mitigation on unpatched systems, limit untrusted web browsing or restrict JavaScript from untrusted sites.

Affected
Google Chromeprior to 80.0.3987.122
Google Chromium V8 (JavaScript engine component)prior to the fix delivered in Chrome 80.0.3987.122
Fedora Project Fedora (Chromium package)Chromium builds with vulnerable V8; distro-specific version numbers not provided in source data
Red Hat Enterprise Linux Desktop (Chromium package)Chromium builds with vulnerable V8; distro-specific version numbers not provided in source data
Red Hat Enterprise Linux Server (Chromium package)Chromium builds with vulnerable V8; distro-specific version numbers not provided in source data
Red Hat Enterprise Linux Workstation (Chromium package)Chromium builds with vulnerable V8; distro-specific version numbers not provided in source data
Debian Linux (Chromium package)Chromium builds with vulnerable V8; distro-specific version numbers not provided in source data
Estimated exposure
massbillions of users/installations (Chrome's global install base runs to billions, and at disclosure in February 2020 every Chrome user on a pre-80.0.3987.122… — Chrome is the world's most widely used browser with a multi-billion install base, and because the flaw was a fixed-in-place zero-day, effectively all users who had not yet auto-updated to 80.0.3987.122 were exposed at the time; today only…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googlefedoraprojectredhatdebian
Products
chrome, fedora, enterprise linux desktop, enterprise linux server, enterprise linux workstation, debian linux
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news