Chrome Gets Patch for a Zero-Day Flaw That’s Being Exploited in the Wild

The Chrome zero-day vulnerability is tracked under CVE-2020-6418 and is described as a "type confusion in V8".

Advertisement
By Jagmeet Singh | Updated: 26 February 2020 11:20 IST
Highlights
  • Google Chrome version 80.0.3987.122 carries the patch
  • The latest Chrome update also fixes two other highly severe issues
  • Google Chrome update is available for Windows, Mac, and Linux users

Google Chrome has received three zero-day fixes in the past year

Google has patched a zero-day vulnerability in Chrome that is being exploited in the wild. The new patch is a part of the latest Chrome update that carries version 80.0.3987.122 for Windows, Mac, and Linux users, the search giant revealed through a blog post. The update is the third in the series of zero-day fixes that Google has brought in the past year. The first zero-day vulnerability was discovered and patched in March last year. It was a part of the Chrome version 72.0.3626.121.

Antti Tikkanen of Google's Threat Analyst Group posted a tweet on Tuesday to announce the patching of the zero-day vulnerability that is tracked under CVE-2020-6418. The Chrome team also separately mentioned in the blog post that the vulnerability was reported by Clement Lecigne of Google's Threat Analysis Group on February 18.

Advertisement

Google is aware of reports that an exploit for CVE-2020-6418 exists in the wild,” the company wrote in the blog post.

It is unclear whether any malicious parties leveraged the security loophole to affect Chrome users. However, the vulnerability has been described as a “type confusion in V8.”

Advertisement

As noted by Catalin Cimpanu of ZDNet, V8 is a component in Google Chrome that is responsible for processing JavaScript code. A community-developed list on the Common Weakness Enumeration (CWE) website states that a “type confusion” refers to the program that allocates or initialises a resource using one type, but it is later tricked to access that resource using a type that is not matching with the original type. Moreover, a bug of type confusion nature could allow attackers to execute unrestricted malicious code within an app.

The Chrome version 80.0.3987.122 that includes the fix for the newly discovered zero-day flaw is available for download for Windows, Mac, and Linux users. The update also contains fixes for two other vulnerabilities that had “high” severity.

Advertisement

In March last year, Google patched the zero-day flaw listed as CVE-2019-5786 that was also reported by Clement Lecigne of the Threat Analysis Group. The second zero-day vulnerability that the search giant fixed in the last one year was tracked by an identifier of CVE-2019-13720 that was patched in November.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Google Chrome, Chrome, Google, zero day
Advertisement

Related Stories

Popular Mobile Brands
  1. Jio Users Can Get Free Incoming SMS Abroad Using Wi-Fi Calling
  2. Oppo A6s 5G With 6,500mAh Battery Launched in India: See Price
  3. Poco X8 Series Arrives in India With 50-Megapixel Camera: See Price
  4. Vivo X300 Ultra, Vivo X300s Will Feature This New Colour Technology
  5. Here's How Much the Samsung Galaxy A57 5G and Galaxy A37 5G Might Cost
  6. Xiaomi 17 Series Goes on Sale in India: See Price, Offers
  7. Garmin Now Lets You Use WhatsApp on These Smartwatch Models
  8. OnePlus 15T Will Be Launched in China Next Week, Company Confirms
  9. Realme P4 Lite 5G Roundup: Price in India, Specifications Expected
  10. Huawei Teases MatePad 11.5 Price in India Ahead of Launch
  1. US SEC Defines Crypto Securities, Signals Clarity for US Traders and Institutions
  2. Samsung Galaxy S26 FE, Galaxy M47 5G and Galaxy F70 Pro 5G Reportedly Surface on GSMA Database
  3. Vivo V70 FE Price in India, Launch Timeline Leaked Days After Global Debut: Expected Price, Specifications
  4. Garmin Introduces WhatsApp App for Select Fenix, Forerunner, Venu Series Smartwatches
  5. AI Can Assist Game Development But Won't Create Hits, Says Take Two CEO Amid DLSS 5 Backlash
  6. iPhone 17e Teardown Video Reveals Repairability Score, Easy MagSafe Upgrade for iPhone 16e
  7. Xiaomi 17T Launch Seems Imminent as Phone Reportedly Bags Singapore's IMDA Certification
  8. Bitcoin Nears Key Resistance Ahead of Anticipated US Fed Policy Decision
  9. Powerbeats Pro 2 Nike Special Edition Launched in India With Apple's H2 Chip, ANC
  10. Xiaomi 17, Xiaomi 17 Ultra With Leica Optics and Snapdragon 8 Elite Gen 5 Chip Go on Sale in India: Price, Offers
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.