For the third time in a year, Google has fixed a Chrome zero-day (CVE-2020-6418) that is being actively exploited by attackers in the wild.
The vulnerability was discovered and reported to the Chromium team by Clement Lecigne of Google’s Threat Analysis Group on February 18.
They released the exploit – which works only if Chrome’s sandbox is disabled or can be bypassed via another vulnerability – and pointed out that it’s a good thing Google has managed to reduce Chrome’s “patch gap” to two weeks.
Vulnerability description:-
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Google released the exploit – which works only if Chrome’s sandbox is disabled or can be bypassed via another vulnerability – and pointed out that it’s a good thing Google has managed to reduce Chrome’s “patch gap” to two weeks.
For more information about the CVE visit-
https://nvd.nist.gov/vuln/detail/CVE-...
Disclaimer:- This video was created for educational purposes and should not be used in environments without legal authorization.
Background Track:- Elektronomia - Sky High
If you like the video do Like, Comment, and share. Any Kind of suggestions is welcome.
Facebook: / ncybersec
Twitter: / nationalcybers1
Website: https://ncybersecurity.com
Email: [email protected]
#GoogleChrome #CVE20206418 #POC