CVE-2020-16040: vulnerability in Google Chrome
Published · Updated
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Google Chrome's V8 engine didn't properly check data before processing it, allowing attackers to corrupt the computer's memory by tricking users into visiting a malicious website.
Insufficient input validation in V8 allowed remote code execution through heap corruption via crafted HTML. Attack vector is web-based (malicious webpage), requires user interaction (visiting the site), and can lead to arbitrary code execution with Chrome process privileges.
In the same product, most dangerous first.