CVE-2020-6418
KEV PoC ×2massType Confusion in Google Chrome's V8 Engine Enables Heap Corruption
CISA: Google Chromium V8 Type Confusion Vulnerability
CVE-2020-6418 is a type confusion vulnerability (CWE-843) in V8, the JavaScript engine used in Google Chrome and Chromium, affecting versions prior to 80.0.3987.122. A remote attacker triggers it by persuading a user to open a crafted HTML page whose JavaScript causes V8 to mishandle object types (public PoCs reference a JSCreate side-effect issue), potentially leading to heap corruption. Successful exploitation can yield arbitrary code execution in the browser, a common stepping stone for further compromise on the victim's system. Any Chrome/Chromium deployment with the vulnerable V8 was affected, including Chromium packages shipped by Fedora, Red Hat Enterprise Linux, and Debian. The flaw was a zero-day exploited in the wild when patched in February 2020; it is listed in CISA KEV (added 2021-11-03) and carries a very high EPSS of 78.8%, making it a priority patch.
What to do: Update Google Chrome to 80.0.3987.122 or later and confirm the running version via chrome://settings/help or chrome://version. Apply the updated Chromium packages from Fedora, Red Hat, and Debian on managed Linux endpoints and check whether any hosts still run pre-fix Chromium. Given the KEV listing and 78.8% EPSS, treat patching as urgent; as an interim mitigation on unpatched systems, limit untrusted web browsing or restrict JavaScript from untrusted sites.
| Google Chrome | prior to 80.0.3987.122 |
| Google Chromium V8 (JavaScript engine component) | prior to the fix delivered in Chrome 80.0.3987.122 |
| Fedora Project Fedora (Chromium package) | Chromium builds with vulnerable V8; distro-specific version numbers not provided in source data |
| Red Hat Enterprise Linux Desktop (Chromium package) | Chromium builds with vulnerable V8; distro-specific version numbers not provided in source data |
| Red Hat Enterprise Linux Server (Chromium package) | Chromium builds with vulnerable V8; distro-specific version numbers not provided in source data |
| Red Hat Enterprise Linux Workstation (Chromium package) | Chromium builds with vulnerable V8; distro-specific version numbers not provided in source data |
| Debian Linux (Chromium package) | Chromium builds with vulnerable V8; distro-specific version numbers not provided in source data |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- Affected
- Google Chromium V8
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- googlefedoraprojectredhatdebian
- Products
- chrome, fedora, enterprise linux desktop, enterprise linux server, enterprise linux workstation, debian linux
- Weakness
- CWE-843
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H