CVE-2018-6065highunder attackCWE-190

CVE-2018-6065: high-severity vulnerability in Google Chrome

Published · Updated

83Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.8epss 60%
from disclosure to weapon0 days
Published on NVDNov 14
1st PoCMay 4
CISA KEV+1302d
exploitation probability
60%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
4 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
3 products (12 components)
Red Hat Enterprise Linux Desktop Supplementary (v. 6) · Red Hat Enterprise Linux Server Supplementary (v. 6) · Red Hat Enterprise Linux Workstation Supplementary (v. 6)
Action required by CISAfederal deadline: 2022-06-22

Apply updates per vendor instructions.

In short

Google Chrome's JavaScript engine had a flaw where it miscalculated memory size when creating objects, allowing attackers to corrupt the browser's memory through a malicious webpage.

Technical detail

Integer overflow in V8's object instantiation allocation size calculation allowed remote attackers to trigger heap corruption via crafted HTML; exploitation requires user to visit attacker-controlled page, potentially leading to code execution or memory-based attacks.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Google · Chrome
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.