CVE-2020-6507
HIGHGoogle Chrome < 83.0.4103.106 - Remote Code Execution via V8 Out of Bounds Write
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-6507. PoCs published by r4j0x00.
AI-analyzed exploit summary This exploit leverages an out-of-bounds write vulnerability in Google Chrome's V8 JavaScript engine to achieve remote code execution. It manipulates array lengths and memory corruption to gain arbitrary read/write capabilities, ultimately overwriting a WebAssembly instance's memory with shellcode.
Description
Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Exploits (1)
This exploit leverages an out-of-bounds write vulnerability in Google Chrome's V8 JavaScript engine to achieve remote code execution. It manipulates array lengths and memory corruption to gain arbitrary read/write capabilities, ultimately overwriting a WebAssembly instance's memory with shellcode.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H