CVE-2018-6065: Google Chromium V8 Integer Overflow Vulnerability
An integer overflow flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=808192
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Other sources
Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
— CISA
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/chromium-browserto a version that resolves this vulnerability.Fixed in 65.0.3325.146 - Upgrade
Upgrade
Chromium-based browsers (V8)to a version that resolves this vulnerability.Fixed in 65.0.3325.146
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-6065.
What is the affected software for this vulnerability?
The affected software for this vulnerability includes Google Chromium V8 Engine, Chromium Browser, libv8, Google Chrome, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server, Redhat Enterprise Linux Workstation, Debian Debian Linux, and Xiaomi Browser.
How can this vulnerability be exploited?
This vulnerability can be exploited by remote attackers who can execute arbitrary code on vulnerable installations of Xiaomi Mi6 Browser through user interaction, such as visiting a malicious page or opening a malicious file.
What is the severity of CVE-2018-6065?
CVE-2018-6065 has a severity rating of 8.8 (High).
Where can I find more information about this vulnerability?
More information about this vulnerability can be found in the references: [Google Code](https://code.google.com/p/chromium/issues/detail?id=808192), [Chrome Releases](https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html), and [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1552502).