CVE-2018-6065 is an integer overflow vulnerability in Google Chrome's V8 JavaScript engine, affecting versions prior to 65.0.3325.146, as well as Debian, Google, Mi, and Red Hat products. This vulnerability has a critical CVSS score of 8.8 (High), indicating it can be exploited remotely with low complexity through user interaction (e.g., visiting a crafted HTML page), leading to potential heap corruption and full compromise (Confidentiality, Integrity, Availability). It is actively exploited in the wild, as evidenced by its presence in the KEV catalog and mentions in threat intelligence reports like the POISON CARP campaign, with public exploit code available via ExploitDB (EDB-44584) and significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 65.0.3325.146CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.