EXPOSURES › CVE-2020-6418
CVE-2020-6418
HIGH ⌖ ON CISA KEV · EXPLOITEDA type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
This vulnerability enabled remote code execution through heap corruption, impacting Google Chrome, Microsoft Edge, and Opera. DIB organizations must ensure their browsers are patched to prevent exploitation, as this was actively exploited in the wild and linked to ransomware campaigns.
Shame score — The vulnerability was actively exploited in the wild and linked to ransomware, indicating a failure to patch known issues before exploitation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
"Google Chromium V8 Engine contains a type confusion vulnerability."
| PRODUCT | STATUS |
|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) Google |
Authorized |
| Google Workspace Google |
Authorized |