chromereleases.googleblog.com
https://chromereleases.googleblog.com/2020/11/chrome-for-android-update.html CVE-2020-16010
CRITICALCISA KEV
Google Chrome for Android UI Heap Buffer Overflow Vulnerability
Record summary
CVE-2020-16010 has a selected CVSS score of 9.6 (critical). CISA lists CVE-2020-16010 in KEV.
Description
Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Nov 3, 2021 · CISA
- VulnCheck KEV
- Listed · Oct 31, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 20, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
ChromeBrowse Google / ChromeDefault status: unknown | CVE List | Before 86.0.4240.185 | affected |
Chrome for Android UIBrowse Google / Chrome for Android UI | CISA | Version data not supplied | |
androidBrowse google / androidDefault status: unknown | CVE List | * | affected |
References
4crbug.com
https://crbug.com/1144368 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-16010 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-16010