CVE-2020-6468
published 2020-05-21CVE-2020-6468: Type confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
PriorityP351high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
6.41%
93.0th percentile
Type confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 83.0.4103.83-1 | 83.0.4103.83-1 |
| chromium | chromium | >= 0 < 83.0.4103.83-1 | 83.0.4103.83-1 |
| chromium | chromium | >= 0 < 83.0.4103.83-1 | 83.0.4103.83-1 |
| chromium | chromium | >= 0 < 83.0.4103.83-1 | 83.0.4103.83-1 |
| debian | chromium | < chromium 83.0.4103.83-1 (bookworm) | chromium 83.0.4103.83-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome | < 83.0.4103.61 | 83.0.4103.61 | |
| chrome | >= unspecified < 83.0.4103.61 | 83.0.4103.61 | |
| chrome_chrome | — | — | |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2020-6468 is a Type Confusion vulnerability in the V8 JavaScript engine of Google Chrome prior to version 83.0.4103.61; detection should focus on identifying unpatched Chrome versions below this threshold ↗
- →The vulnerability is triggered via a crafted HTML page delivered remotely; monitor for suspicious or anomalous HTML/JS content targeting V8 type confusion patterns in web traffic ↗
- →Chromium upstream bug tracker ID 1076708 is associated with this CVE and may contain PoC or technical details useful for building detections ↗
- ·Fixed version for Debian (all tracked branches) is 83.0.4103.83-1, which is slightly newer than the upstream fix version of 83.0.4103.61; ensure the correct fixed version is used per platform when writing version-based detections ↗
- ·Red Hat Enterprise Linux 6 Supplementary addressed this issue via RHSA-2020:2544; version-based detections on RHEL should reference this advisory rather than the upstream Chrome version alone ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: Type Confusion in V8
vendor_redhat·2020-05-19·CVSS 8.8
CVE-2020-6468 [HIGH] chromium-browser: Type Confusion in V8
chromium-browser: Type Confusion in V8
Type confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Chrome
Stable Channel Update for Desktop: CVE-2020-6467
vendor_chrome·2020-05-19·CVSS 8.8
CVE-2020-6467 [HIGH] Stable Channel Update for Desktop: CVE-2020-6467
Stable Channel Update for Desktop
CVE-2020-6467: Use after free in WebRTC. Reported by ZhanJia Song on 2020-04-06
[$7500][ 1076708 ] High CVE-2020-6468: Type Confusion in V8
Reported by Chris Salls and Jake Corina of Seaside Security, Chani Jindal of Shellphish on 2020-04-30
Severity: high
Debian
CVE-2020-6468: chromium - Type confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote att...
vendor_debian·2020·CVSS 8.8
CVE-2020-6468 [HIGH] CVE-2020-6468: chromium - Type confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote att...
Type confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved (fixed in 83.0.4103.83-1)
sid: resolved (fixed in 83.0.4103.83-1)
trixie: resolved (fixed in 83.0.4103.83-1)
GHSA
GHSA-9ch6-gr3w-j9vf: Type confusion in V8 in Google Chrome prior to 83
ghsa_unreviewed·2022-05-24
CVE-2020-6468 [MEDIUM] CWE-787 GHSA-9ch6-gr3w-j9vf: Type confusion in V8 in Google Chrome prior to 83
Type confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
OSV
CVE-2020-6468: Type confusion in V8 in Google Chrome prior to 83
osv·2020-05-21·CVSS 8.8
CVE-2020-6468 [HIGH] CVE-2020-6468: Type confusion in V8 in Google Chrome prior to 83
Type confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-6468 chromium-browser: Type Confusion in V8
bugzilla·2020-05-20·CVSS 8.8
CVE-2020-6468 [HIGH] CVE-2020-6468 chromium-browser: Type Confusion in V8
CVE-2020-6468 chromium-browser: Type Confusion in V8
A type confusion flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1076708
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6468
Bugzilla
CVE-2020-6465 CVE-2020-6466 CVE-2020-6467 CVE-2020-6468 CVE-2020-6470 CVE-2020-6471 CVE-2020-6472 CVE-2020-6473 CVE-2020-6474 CVE-2020-6475 CVE-2020-6477 CVE-2020-6478 CVE-2020-6480 CVE-2020-6481 CVE-
bugzilla·2020-05-20·CVSS 9.6
CVE-2020-6465 [CRITICAL] CVE-2020-6465 CVE-2020-6466 CVE-2020-6467 CVE-2020-6468 CVE-2020-6470 CVE-2020-6471 CVE-2020-6472 CVE-2020-6473 CVE-2020-6474 CVE-2020-6475 CVE-2020-6477 CVE-2020-6478 CVE-2020-6480 CVE-2020-6481 CVE-
CVE-2020-6465 CVE-2020-6466 CVE-2020-6467 CVE-2020-6468 CVE-2020-6470 CVE-2020-6471 CVE-2020-6472 CVE-2020-6473 CVE-2020-6474 CVE-2020-6475 CVE-2020-6477 CVE-2020-6478 CVE-2020-6480 CVE-2020-6481 CVE-2020-6482 ... chromium: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the releva
Bugzilla
CVE-2020-6465 CVE-2020-6466 CVE-2020-6467 CVE-2020-6468 CVE-2020-6470 CVE-2020-6471 CVE-2020-6472 CVE-2020-6473 CVE-2020-6474 CVE-2020-6475 CVE-2020-6477 CVE-2020-6478 CVE-2020-6480 CVE-2020-6481 CVE-
bugzilla·2020-05-20·CVSS 9.6
CVE-2020-6465 [CRITICAL] CVE-2020-6465 CVE-2020-6466 CVE-2020-6467 CVE-2020-6468 CVE-2020-6470 CVE-2020-6471 CVE-2020-6472 CVE-2020-6473 CVE-2020-6474 CVE-2020-6475 CVE-2020-6477 CVE-2020-6478 CVE-2020-6480 CVE-2020-6481 CVE-
CVE-2020-6465 CVE-2020-6466 CVE-2020-6467 CVE-2020-6468 CVE-2020-6470 CVE-2020-6471 CVE-2020-6472 CVE-2020-6473 CVE-2020-6474 CVE-2020-6475 CVE-2020-6477 CVE-2020-6478 CVE-2020-6480 CVE-2020-6481 CVE-2020-6482 ... chromium: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant t
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-06/msg00038.htmlhttps://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.htmlhttps://crbug.com/1076708https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OQYH5OK7O4BU6E37WWG5SEEHV65BFSGR/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLFZ5N4EK6I4ZJP5YSKLLVN3ELXEB4XT/https://security.gentoo.org/glsa/202006-02https://www.debian.org/security/2020/dsa-4714http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-06/msg00038.htmlhttps://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.htmlhttps://crbug.com/1076708https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OQYH5OK7O4BU6E37WWG5SEEHV65BFSGR/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLFZ5N4EK6I4ZJP5YSKLLVN3ELXEB4XT/https://security.gentoo.org/glsa/202006-02https://www.debian.org/security/2020/dsa-4714
2020-05-21
Published