chromereleases.googleblog.com
https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop_11.html CVE-2020-16017
CRITICALCISA KEV
Use after free in CefSharp
Record summary
CVE-2020-16017 has a selected CVSS score of 9.6 (critical). CISA lists CVE-2020-16017 in KEV.
Description
Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Nov 3, 2021 · CISA
- VulnCheck KEV
- Listed · Nov 7, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 3, 2025 · Source: CVE List
Affected products and versions
5| Product | Source | Version range | Status |
|---|---|---|---|
ChromeBrowse Google / Chrome | CISA, CVE List | Before 86.0.4240.198 | affected |
CefSharp.CommonBrowse NuGet / CefSharp.Common | GitHub Advisory | Before 86.0.241 · Fixed in 86.0.241 | affected |
CefSharp.WinFormsBrowse NuGet / CefSharp.WinForms | GitHub Advisory | Before 86.0.241 · Fixed in 86.0.241 | affected |
CefSharp.WpfBrowse NuGet / CefSharp.Wpf | GitHub Advisory | Before 86.0.241 · Fixed in 86.0.241 | affected |
CefSharp.Wpf.HwndHostBrowse NuGet / CefSharp.Wpf.HwndHost | GitHub Advisory | Before 86.0.241 · Fixed in 86.0.241 | affected |
References
5crbug.com
https://crbug.com/1146709 github.com
https://github.com/cefsharp/CefSharp/security/advisories/GHSA-gvqv-779r-4jgp nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-16017 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-16017