CVE-2020-6514

MEDIUM

Google Chrome < 84.0.4147.89 - Heap Corruption via Crafted SCTP Stream

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2020-6514. PoCs published by hasan-khalil.

AI-analyzed exploit summary This repository contains functional exploit code for CVE-2020-6514, targeting WebRTC implementations in applications like Duo, JioChat, VK, OK, and Signal. The exploit leverages memory corruption in the SCTP/SRTP handling to achieve remote code execution (RCE) by manipulating vtables and function pointers.

Description

Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.

Exploits (4)

nomisec WORKING POC 2 stars
by hasan-khalil · poc
https://github.com/hasan-khalil/CVE-2020-6514

This repository contains functional exploit code for CVE-2020-6514, targeting WebRTC implementations in applications like Duo, JioChat, VK, OK, and Signal. The exploit leverages memory corruption in the SCTP/SRTP handling to achieve remote code execution (RCE) by manipulating vtables and function pointers.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: WebRTC-based applications (e.g., Duo, JioChat, VK, OK, Signal)
No auth needed
Prerequisites: Target must be using vulnerable WebRTC implementation · Attacker must establish a WebRTC connection with the target
devstral-2 · analyzed Feb 18, 2026 Full analysis →
inthewild WORKING POC
poc
https://github.com/rojhack/cve-2020-6514

This repository contains functional exploit code for CVE-2020-6514, targeting WebRTC implementations in applications like Duo, JioChat, VK, OK, and Signal. The exploit leverages memory corruption in the SCTP/SRTP handling to achieve remote code execution (RCE) by manipulating vtables and heap structures.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: WebRTC implementations (libringrtc_rffi.so, usrsctp, etc.)
No auth needed
Prerequisites: Target must initiate a WebRTC call · Exploit must be injected into the call flow
devstral-2 · analyzed Feb 23, 2026 Full analysis →
inthewild WORKING POC
poc
https://github.com/r0jhack/cve-2020-6514

This repository contains functional exploit code for CVE-2020-6514, targeting WebRTC implementations in applications like Duo, JioChat, VK, OK, and Signal. The exploit leverages memory corruption in the SCTP/SRTP handling to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: WebRTC implementations (libringrtc_rffi.so)
No auth needed
Prerequisites: Target must initiate a WebRTC call · Exploit must be injected into the WebRTC session
devstral-2 · analyzed Feb 23, 2026 Full analysis →
inthewild WORKING POC
poc
https://github.com/hassanazze/cve-2020-6514

This repository contains functional exploit code for CVE-2020-6514, targeting WebRTC implementations in multiple applications (Duo, JioChat, VK, OK, Signal). The exploit leverages memory corruption in the SCTP/SRTP handling to achieve remote code execution (RCE) by manipulating vtables and exploiting predictable PRNG states.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: WebRTC-based applications (Duo, JioChat, VK, OK, Signal)
No auth needed
Prerequisites: Target must initiate a WebRTC call · Exploit requires precise memory manipulation and timing
devstral-2 · analyzed Feb 23, 2026 Full analysis →

References (27)

Core 27
Core References
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT211288
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT211290
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT211291
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT211292
Exploit, Issue Tracking, Vendor Advisory x_refsource_misc
https://crbug.com/1076703
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00069.html
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202007-08
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2020/07/msg00027.html
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2020/dsa-4736
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202007-64
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/158697/WebRTC-usrsctp-Incorrect-Call.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2020/08/msg00006.html
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2020/dsa-4740
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00008.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00007.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00011.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00018.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00022.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00025.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00032.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4443-1/
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00041.html
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2021/dsa-4824
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202101-30

Scores

CVSS v3 6.5
EPSS 0.1056
EPSS Percentile 93.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

CWE
CWE-200
Status published
Products (16)
apple/ipados < 13.6
apple/iphone_os < 13.6
apple/safari < 13.1.2
apple/tvos < 13.4.8
apple/watchos < 6.2.8
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 20.04
debian/debian_linux 9.0
debian/debian_linux 10.0
... and 6 more
Published Jul 22, 2020
Tracked Since Feb 18, 2026