CVE-2020-16009: high-severity vulnerability in Google Chrome
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
Google Chrome's V8 JavaScript engine had a flaw that could let attackers corrupt memory on your computer through a malicious website. This could crash your browser or potentially allow unauthorized access to your system.
CWE-787 (out-of-bounds write) and CWE-843 (type confusion) in V8 JavaScript engine prior to version 86.0.4240.183 allowed remote attackers to trigger heap corruption via crafted HTML. Attack vector is network-based (malicious webpage), requiring user interaction; impact includes code execution and system compromise.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.