CVE-2020-15999criticalunder attackCWE-120

CVE-2020-15999: critical vulnerability in Google Chrome

Published · Updated

90Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 9.6epss 64%
from disclosure to weapon1 days
Published on NVDNov 3
1st PoC+1d
CISA KEV+365d
exploitation probability
64%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
5 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
15 products (162 components)
Red Hat Enterprise Linux BaseOS (v. 8) · Red Hat Enterprise Linux BaseOS EUS (v. 8.1) · Red Hat Enterprise Linux BaseOS EUS (v. 8.2) · Red Hat Enterprise Linux Server (v. 7) · Red Hat Enterprise Linux BaseOS E4S (v. 8.0) · and others 10
Not affected
3 products (10 components) — because the vulnerable code is not present in the product
Red Hat Enterprise Linux 6 · Red Hat Advanced Cluster Management for Kubernetes 2 · Red Hat Enterprise Linux 5
Action required by CISAfederal deadline: 2021-11-17

Apply updates per vendor instructions.

In short

A flaw in the font-handling library (Freetype) used by Chrome allows an attacker to corrupt computer memory through a specially designed webpage. This could enable the attacker to execute malicious code or crash the browser.

Technical detail

Heap buffer overflow in Freetype's font parsing allows a remote attacker to write beyond allocated memory boundaries via crafted HTML. Exploitation requires user to visit a malicious webpage; successful exploitation results in heap corruption leading to potential code execution or denial of service.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected products
Google · Chrome
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.