CVE-2020-16009highunder attackCWE-787CWE-843

CVE-2020-16009: high-severity vulnerability in Google Chrome

Published · Updated

83Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.8epss 48%
from disclosure to weapon
Published on NVDNov 3
CISA KEV+365d
exploitation probability
48%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
4 products (14 components)
Red Hat Enterprise Linux Desktop Supplementary (v. 6) · Red Hat Enterprise Linux Server Supplementary (v. 6) · Red Hat Enterprise Linux Workstation Supplementary (v. 6) · Red Hat Enterprise Linux HPC Node Supplementary (v. 6)
Action required by CISAfederal deadline: 2022-05-03

Apply updates per vendor instructions.

In short

Google Chrome's V8 JavaScript engine had a flaw that could let attackers corrupt memory on your computer through a malicious website. This could crash your browser or potentially allow unauthorized access to your system.

Technical detail

CWE-787 (out-of-bounds write) and CWE-843 (type confusion) in V8 JavaScript engine prior to version 86.0.4240.183 allowed remote attackers to trigger heap corruption via crafted HTML. Attack vector is network-based (malicious webpage), requiring user interaction; impact includes code execution and system compromise.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Google · Chrome
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.