Record summary

CVE-2020-16017 has a selected CVSS score of 9.6 (critical). CISA lists CVE-2020-16017 in KEV.

Description

Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Nov 3, 2021 · CISA
VulnCheck KEV
Listed · Nov 7, 2020 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 3, 2025 · Source: CVE List

Affected products and versions

5
ProductSourceVersion rangeStatus
CISA, CVE ListBefore 86.0.4240.198affected
GitHub AdvisoryBefore 86.0.241 · Fixed in 86.0.241affected
GitHub AdvisoryBefore 86.0.241 · Fixed in 86.0.241affected
GitHub AdvisoryBefore 86.0.241 · Fixed in 86.0.241affected
GitHub AdvisoryBefore 86.0.241 · Fixed in 86.0.241affected

References

5