Record summary

CVE-2020-16009 has a selected CVSS score of 8.8 (high). CISA lists CVE-2020-16009 in KEV.

Description

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Nov 3, 2021 · CISA
VulnCheck KEV
Listed · Oct 29, 2020 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List

Affected products and versions

6
ProductSourceVersion rangeStatus
CVE ListBefore 86.0.4240.183affected
CISAVersion data not supplied
GitHub AdvisoryBefore 86.0.241 · Fixed in 86.0.241affected
GitHub AdvisoryBefore 86.0.241 · Fixed in 86.0.241affected
GitHub AdvisoryBefore 86.0.241 · Fixed in 86.0.241affected
GitHub AdvisoryBefore 86.0.241 · Fixed in 86.0.241affected

References

Showing 12 of 15