CVE-2018-6065: high-severity vulnerability in Google Chrome
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
Google Chrome's JavaScript engine had a flaw where it miscalculated memory size when creating objects, allowing attackers to corrupt the browser's memory through a malicious webpage.
Integer overflow in V8's object instantiation allocation size calculation allowed remote attackers to trigger heap corruption via crafted HTML; exploitation requires user to visit attacker-controlled page, potentially leading to code execution or memory-based attacks.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.