← back
CVE-2020-16013

CVE-2020-16013

CVSS 8.8 HIGHEPSS 2.8%● KEVCWE-787
In short

Google Chrome's V8 JavaScript engine had a flaw that could allow attackers to corrupt memory on your computer through a malicious webpage, potentially leading to crashes or unauthorized access.

Technical detail

An out-of-bounds write vulnerability (CWE-787) in V8's implementation prior to v86.0.4240.198 allows remote attackers to trigger heap corruption via specially crafted HTML. Exploitation requires user interaction (visiting a malicious page) and can result in arbitrary code execution or denial of service.

Summary generated and translated by AI from the official description.
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Google · Chrome

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →