CVE-2020-6418: high-severity vulnerability in Google Chrome
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
Google Chrome's JavaScript engine (V8) had a flaw where it confused different data types, allowing attackers to corrupt computer memory through a malicious webpage. This could lead to crashes or arbitrary code execution.
Type confusion vulnerability in V8 allows remote attackers to trigger heap corruption by crafting malicious HTML pages that exploit incorrect type handling during JavaScript execution. Exploitation requires user interaction to visit a crafted page; successful exploitation can result in arbitrary code execution with browser privileges.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.