CVE-2020-6418 is a type-confusion vulnerability in the V8 JavaScript engine used by Google Chrome before version 80.0.3987.122. The flaw is in TurboFan's Map-reliability analysis, specifically InferMapsUnsafe. A JSCreate operation generated while optimizing an inlined Reflect.construct call was not modeled as a side effect that could invalidate an object's Map. TurboFan could consequently omit required Map checks after a Proxy-triggered object-layout change, operating under a stale type and element-size assumption. This can confuse object and double-array representations, producing out-of-bounds heap access and heap corruption from attacker-controlled JavaScript in a crafted web page.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a real exploit chain combining a browser RCE with a Windows local privilege escalation. It is not just a PoC snippet: it contains a working browser stage, native shellcode, a standalone Windows EoP binary, build scripts, prebuilt artifacts, and notes documenting an abandoned delivery approach. Structure: the root README explains the full chain and operator workflow. browser-exploit/ contains the Chrome CVE-2020-6418 exploit as a static HTML/JavaScript file plus a Python builder that embeds shellcode into the page. browser-exploit/shellcode/ contains x64 assembly stubs and a C harness for testing shellcode outside the browser. privilege-escalation/ contains a large standalone C exploit for Windows 10 20H1 build 19041.264. notes/ contains earlier unused stubs and a test harness for a failed approach that tried to push the full PE through the V8 arbitrary write primitive. prebuilt/ contains ready-made exploit.html and references to exploit.exe. Main capability: exploit_template.html abuses CVE-2020-6418 in V8 Turbofan to corrupt a Float64Array length, build relative and absolute read/write primitives, locate a WebAssembly RWX page, and overwrite it with native shellcode. The shellcode is not a full payload; it is a downloader/launcher stub. That stub manually resolves Windows APIs by walking the PEB and PE export tables, loads urlmon.dll, calls URLDownloadToFileA to fetch a second-stage executable from an attacker-controlled HTTP server, saves it to disk, and launches it with WinExec. Second stage: privilege-escalation/exploit.c is a standalone local privilege escalation tool targeting Windows 10 20H1 build 19041.264 x64. According to the code and documentation, it first recovers the kernel base using a PREFETCH+RDTSCP timing side channel, then abuses a missing length check in NtPowerInformation BootStat integrity handling to gain a write-{0,1} primitive against an arbitrary kernel address, specifically to disable ExIsRestrictedCaller protections by modifying SepMediumDaclSd-related state. It then uses CVE-2021-31956 in ntfs.sys Extended Attribute handling to establish a stable arbitrary kernel read/write primitive via named pipe attributes. With that primitive, it locates SYSTEM’s token and copies it into the current process, then spawns a SYSTEM shell and attempts cleanup/repair of kernel state. Operational notes: the exploit is highly version-specific and depends on hardcoded offsets in both the browser and kernel stages. It requires Chrome 80.0.3987.87 x64, Windows 10 19041.264 x64, and Chrome launched with --no-sandbox. The default second-stage URL is hardcoded as http://192.168.37.1:8000/exploit.exe, and the default drop path is C:\lab8\exploit.exe. The repository’s prebuilt exploit.html embeds that same network configuration. Overall maturity is OPERATIONAL: the payload is functional and complete, but configuration is largely hardcoded rather than framework-driven.
This repository contains a single Metasploit module: 'chrome_jscreate_sideeffect.rb', which exploits CVE-2020-6418, a type confusion vulnerability in Google Chrome 80.0.3987.87 (64 bit) on Windows 10 and macOS. The exploit is delivered via a malicious HTTP server that serves a crafted HTML/JavaScript payload to the victim's browser. The JavaScript code manipulates array structures to achieve out-of-bounds read/write, then leverages WebAssembly to allocate RWX memory, into which attacker-supplied shellcode is written and executed. The exploit requires the browser to be run with the '--no-sandbox' flag for successful code execution. The module is operational and provides remote code execution in the context of the Chrome renderer process. The only fingerprintable endpoint is the root path ("/") of the HTTP server set up by the Metasploit module to deliver the exploit. The repository is structured as a typical Metasploit exploit module, written in Ruby, with embedded JavaScript for the browser-side exploit.
This repository contains a proof-of-concept (PoC) exploit for CVE-2020-6418, a type confusion vulnerability in the V8 JavaScript engine (used in Google Chrome). The repository consists of two files: a README.md with environment setup and references, and the main exploit script cve_2020_6418_exploit.js. The exploit script demonstrates how to achieve out-of-bounds (OOB) array access in V8, which is then leveraged to gain arbitrary read/write primitives. Using these primitives, the exploit locates a WebAssembly function's code address and injects native shellcode, ultimately achieving arbitrary code execution. The exploit is operational and demonstrates a full sandbox escape, but does not include a full browser sandbox escape (as noted in the README). No network or file endpoints are hardcoded in the exploit; it is a local, browser-based attack requiring the ability to execute JavaScript in a vulnerable V8 environment.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A publicly known V8 JavaScript engine memory corruption vulnerability referenced as part of a prior Foxit PDF Reader RCE case involving an outdated embedded V8 version.
A prior V8 vulnerability referenced as having a similar Map-inference issue involving JSCreate nodes.
A type-confusion vulnerability in Chromium's V8 JavaScript engine addressed by the Chromium 80.0.3987.122 update.
A newer Chromium vulnerability incorporated into the MOONSHINE exploit kit and used in the wild to compromise Android apps with embedded vulnerable Chrome or TBS engines.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.