peter bassill · operator
$ cve CVE-2020-6507 JSON

CVE-2020-6507 EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 19.1% (pctl 97)

Patch early

A public exploit exists.

Description

Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS19.08% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2020-07-22
Last modified2026-06-17

Affected (1)

VendorProduct
googlechrome

Public exploits

SourceTitleDate
exploit-dbGoogle Chrome 81.0.4044 V8 - Remote Code Execution2021-04-06

References

→ the Explorer  ·  watch your stack  ·  NVD