cbcvebase.
CVE-2020-16009
published 2020-11-03

CVE-2020-16009: Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

PriorityP187high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
48.57%
98.7th percentile
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Affected

17 ranges
VendorProductVersion rangeFixed in
cefsharpcefsharp< 86.0.24186.0.241
chromiumchromium>= 0 < 87.0.4280.88-0.187.0.4280.88-0.1
chromiumchromium>= 0 < 87.0.4280.88-0.187.0.4280.88-0.1
chromiumchromium>= 0 < 87.0.4280.88-0.187.0.4280.88-0.1
chromiumchromium>= 0 < 87.0.4280.88-0.187.0.4280.88-0.1
debianchromium< chromium 87.0.4280.88-0.1 (bookworm)chromium 87.0.4280.88-0.1 (bookworm)
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
googlechrome< 86.0.4240.18386.0.4240.183
googlechrome>= unspecified < 86.0.4240.18386.0.4240.183
googlechrome_chrome
microsoftedge< 86.0.622.6386.0.622.63
microsoftedge_chromium< 86.0.4240.18386.0.4240.183
opensusebackports_sle
opensuseleap
opensuseleap

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2020-16009 is a V8 type confusion / inappropriate implementation vulnerability exploited in the wild via a crafted HTML page, enabling heap corruption and remote code execution in Google Chrome prior to 86.0.4240.183
  • The vulnerability is classified as an Out-of-Bounds Write (CWE-787) in V8; detection should focus on crafted HTML pages triggering heap corruption in Chrome/Chromium-based browsers (including embedded CefSharp) before version 86.0.4240.183
  • Flag as high-severity any Google Chromium V8 engine type confusion activity; the vulnerability affects multiple Chromium-based browsers including Google Chrome, Microsoft Edge, and Opera
  • CVE-2020-16009 is tracked as High severity; the bug is in the V8 JavaScript engine component (Chromium bug 1143772)
  • ·Fixed version for Google Chrome is 86.0.4240.183 and later; Debian resolved the issue in chromium 87.0.4280.88-0.1 across all tracked branches
  • ·Rockwell Automation Connected Components Workbench (CefSharp 81.3.100) is also affected; remediation requires upgrade to R21 or later

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa8.8HIGH
osv8.8HIGH
vulncheck9.6CRITICAL
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.