CVE-2020-15969

HIGH

Google Chrome < 86.0.4240.75 - Use-After-Free in WebRTC

Title source: llm
STIX 2.1

Description

Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

References (18)

Core 18
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://crbug.com/1124659
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00016.html
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT212009
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT212011
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT212005
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT212003
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT212007
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2020/Dec/27
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2020/Dec/30
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2020/Dec/24
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2020/Dec/26
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2020/Dec/29
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2021/dsa-4824
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202101-30

Scores

CVSS v3 8.8
EPSS 0.0316
EPSS Percentile 87.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-416 CWE-787
Status published
Products (12)
apple/ipados < 14.3
apple/iphone_os < 14.3
apple/macos < 11.1
apple/safari < 14.0.2
apple/tvos < 14.3
apple/watchos < 7.2
debian/debian_linux 10.0
fedoraproject/fedora 31
fedoraproject/fedora 32
fedoraproject/fedora 33
... and 2 more
Published Nov 03, 2020
Tracked Since Feb 18, 2026