Integer overflow in Google Chrome - CVE-2018-6065
Published: April 5, 2018 / Updated: June 8, 2022
Vulnerability identifier: #VU11562
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-6065
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists due to integer overflow. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists due to integer overflow. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
Google Chrome
Debian Linux
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
SUSE Linux
www-client/chromium
www-client/google-chrome
Debian Linux
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
SUSE Linux
www-client/chromium
www-client/google-chrome
How to mitigate CVE-2018-6065
Update to version 65.0.3325.146.
Google Chrome - update to 65.0.3325.146
www-client/chromium - update to 65.0.3325.146
www-client/google-chrome - update to 65.0.3325.146
www-client/chromium - update to 65.0.3325.146
www-client/google-chrome - update to 65.0.3325.146