Skip to content
COOEY

EXPOSURES › CVE-2018-6065

CVE-2018-6065

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-06-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-6065 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

A heap corruption vulnerability in Google's Chromium V8 engine was actively exploited, impacting browsers like Chrome and Edge, potentially allowing attackers to execute arbitrary code via crafted HTML pages.

An integer overflow in the Chromium V8 engine allowed for heap corruption, which was actively exploited in the wild. DIB organizations using Chromium-based browsers must ensure timely patching to prevent potential code execution and data compromise, directly impacting NIST 800-171 controls related to data protection. Verify browser versions and patch management processes.

Shame score — The vulnerability's active exploitation and potential for code execution in widely used browsers demonstrates a significant security oversight with broad impact.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized