KEVIntel
8.8
CVSS
High

CVE-2018-6065

PUBLISHED

Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146...

Exploited in the wild Remote Low complexity
Vendor
Google
Product
Chrome
Published
Nov 14, 2018
EPSS

Description

Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

java cisa

CVSS scores

CVSS v3.1 8.8 High

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2.0 6.8

AV:N/AC:M/Au:N/C:P/I:P/A:P

Exploitation status

Exploited in the wild

Recorded 2022-06-08 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Jun 08, 2022

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

b1tg/CVE-2018-6065-exploit

github · Created 2021-04-24 12:04:27 UTC · 2 stars

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel