CVE-2020-15999: critical vulnerability in Google Chrome
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
A flaw in the font-handling library (Freetype) used by Chrome allows an attacker to corrupt computer memory through a specially designed webpage. This could enable the attacker to execute malicious code or crash the browser.
Heap buffer overflow in Freetype's font parsing allows a remote attacker to write beyond allocated memory boundaries via crafted HTML. Exploitation requires user to visit a malicious webpage; successful exploitation results in heap corruption leading to potential code execution or denial of service.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.