Type Confusion in Google Chrome - CVE-2020-6418
Published: February 25, 2020 / Updated: February 22, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a type confusion error in V8 component. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger a type confusion error and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Note: This vulnerability is being actively exploited in the wild.
Affected software
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Fedora
Opensuse
SUSE Package Hub for SUSE Linux Enterprise
chromium (Debian package)
www-client/chromium
www-client/google-chrome
chromium
How to mitigate CVE-2020-6418
chromium (Debian package) - update to 80.0.3987.132-1~deb10u1
www-client/chromium - update to 80.0.3987.132
www-client/google-chrome - update to 80.0.3987.132
chromium - addressed in versions 80.0.3987.132-1.el8, 80.0.3987.132-1.fc30, 80.0.3987.132-1.fc31, 80.0.3987.149-1.el8, 80.0.3987.149-1.fc30, 80.0.3987.162-1.el8, 80.0.3987.163-1.el8, 81.0.4044.113-1.el8, 81.0.4044.113-2.el8, 81.0.4044.122-1.el8, 81.0.4044.138-1.el8
Links to Public Exploits and PoC-codes
- Exploit #7371 - ChromeSHELFLoader (An exploit for CVE-2020-6418 implementing a SHELF Loader. Published as part of Tmp.0ut volume 2) (February 22, 2022)
- Exploit #6650 - CVE (A collection of proof-of-concept exploit scripts written by the STAR Labs team for various CVEs that they discovered or found by others.) (August 23, 2021)
- Exploit #5744 - Google Chrome 80 - JSCreate Side-effect Type Confusion (Metasploit) (June 17, 2021)
- Exploit #5330 - cve-2020_6418-exploit (cve-2020_6418-exploittt.js) (May 3, 2021)
- Exploit #4642 - CVE-Vulnerability (A record of some vulnerabilities, as well as some detection and exploitation scripts) (September 21, 2020)
- Exploit #4600 - CVE-2020-6418-PoC (for 供養) (September 16, 2020)
- Exploit #3036 - CVE_2020_6418_PoC (for 供養) (June 19, 2020)
- Exploit #333 - CVE-2020-6418 (PoC of CVE) (March 18, 2020)
- Exploit #1475 - Google Chrome 80 JSCreate side-effect type confusion exploit (March 18, 2020)
External References
Related Security Bulletins
- Multiple vulnerabilities in Google Chrome
- Arch Linux update for chromium
- OpenSUSE Linux update for chromium
- OpenSUSE Linux update for chromium
- Red Hat update for chromium-browser
- Debian update for chromium
- Gentoo update for Chromium, Google Chrome
- Fedora EPEL 8 update for chromium
- Fedora 31 update for chromium
- Fedora 30 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora 30 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora EPEL 8 update for chromium