Researchers detailed exploitation of CVE-2020-6418, a type confusion flaw in Google Chrome’s V8 JavaScript engine that affects versions before 80.0.3987.122. The bug lies in Turbofan’s handling of JSCreate within InferMapsUnsafe, where incorrect side-effect modeling can cause modified object Maps to be treated as trustworthy, skipping required Map checks and enabling out-of-bounds memory access. The write-up shows that a Proxy supplied through Reflect.construct() can trigger the condition and produce out-of-bounds read/write primitives inside the V8 sandbox.
The research further demonstrates a practical exploitation path that avoids the common WebAssembly RWX approach by redirecting a JIT-compiled function’s code_entry_point to attacker-controlled immediate values already embedded in executable JIT code. The authors said they recreated the vulnerability in a newer V8 version using the original patch context and completed a demo exploit in d8, while a later reference highlights continued public interest in using AI assistance to develop Chrome exploit chains around browser vulnerabilities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
STAR Labs published a detailed write-up deconstructing CVE-2020-6418, explaining the root cause in V8's Turbofan compiler and showing how the flaw can be triggered via Proxy and Reflect.construct(). The article also demonstrated a working exploitation path to achieve out-of-bounds access and code execution primitives in a recreated environment.
Google addressed CVE-2020-6418, a type confusion vulnerability in Chrome's V8 JavaScript engine affecting versions prior to 80.0.3987.122. The STAR Labs analysis identifies the bug as fixed by the original patch context for Chrome 80.0.3987.122.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.