EXPOSURES › CVE-2018-6065
CVE-2018-6065
HIGH ⌖ ON CISA KEV · EXPLOITEDA heap corruption vulnerability in Google's Chromium V8 engine was actively exploited, impacting browsers like Chrome and Edge, potentially allowing attackers to execute arbitrary code via crafted HTML pages.
An integer overflow in the Chromium V8 engine allowed for heap corruption, which was actively exploited in the wild. DIB organizations using Chromium-based browsers must ensure timely patching to prevent potential code execution and data compromise, directly impacting NIST 800-171 controls related to data protection. Verify browser versions and patch management processes.
Shame score — The vulnerability's active exploitation and potential for code execution in widely used browsers demonstrates a significant security oversight with broad impact.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
| PRODUCT | STATUS |
|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) Google |
Authorized |
| Google Workspace Google |
Authorized |