SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Alert : Google Chrome Zero-Day vulnerability being exploited in the wild

Alert : Google Chrome Zero-Day vulnerability being exploited in the wild

Feb 25, 2020By Nitish B3 min read

In a bid to fix three new vulnerabilities in its browser, Google has issued updates for Chrome on all the major platforms (google chrome zero day vulnerability). The search giant published an advisory to address the high-severity vulnerabilities, with the most severe one leading to arbitrary code execution and claimed by the Google Development Team as “being exploited in the wild“. These vulnerabilities also affect Microsoft’s Chromium-based edge browser and addressed in the Microsoft Advisory. Also, a vulnerability management tool will be useful here.

The first vulnerability, which assigned by google chrome zero day vulnerability CVE-2020-6418, is a Type Confusion vulnerability and associated with a side-effect in Chrome’s V8 Engine. However, a patch management tool can patch this up. V8 is an open-source engine by Chrome and Chromium browsers to process JavaScript. A type confusion basically revolves around wrong function pointers or data being fed to the wrong block of code.

In this case, as per reports, the attacker uses a similar concept to alter the length of an array to an arbitrary value to gain access to the V8 memory heap. This can lead to arbitrary code execution within the browser sandbox. By default, Chrome does not run without its sandbox enabled, and the attacker would evidently require to launch this attack in conjunction with a sandbox escape in order to take over a device.

The second security flaw is an out of bounds memory access vulnerability and tracked as CVE-2020-6407. This vulnerability associated with the streams API, which to break down and process a resource, bit by bit.

The third vulnerability, which not assigned a CVE, arises due to an Integer Overflow in ICU.

In its habitual approach, Google has not disclosed additional information about any of the vulnerabilities to avoid large-scale exploits and buy some time for its users to secure their browsers.

Proof of Concept

A proof of concept exploit published by a group of researchers from Exodus Intelligence. However, as mentioned before, it can used to execute code within the sandbox.

Affected products

Google Chrome versions before 80.0.3987.122
Microsoft Chromium-based Edge versions before 80.0.361.62

Impact

These vulnerabilities could allow a remote attacker to execute arbitrary code on the affected systems.

Solution

Please refer to this KB Article, which is now replaced by KB Article, to apply the patches using SanerNow.

SecPod Saner detects these vulnerabilities and automatically fixes them by applying security updates. Download SanerNow and keep your systems updated and secure.

Featured Posts

Open CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials
CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

CVE Research

CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

Two MikroTik RouterOS CVEs entered CISA KEV seven days after production fixes. Dated reporting places SSH-chain exploitation involving CVE-2026-86060 at least one calendar day before those releases; no comparable start date is established for CVE-2026-67277.

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch
Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

CVE Research

Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

Four vulnerabilities added to CISA’s KEV catalog on September 9, 2026 show widely different timelines between public disclosure and formal exploitation-based prioritization, ranging from one day to 239 days.

Sep 24, 2026

Open TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

CVE Research

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

A chronological look at how a long-running China-nexus espionage cluster evolved from server-side exploitation to a chained Chrome/Windows zero-day kit — and what that shift signals.

Sep 24, 2026