Junglewise Threat Intelligence

CVE-2020-16009: Inappropriate implementation in V8

CVE-2020-16009 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2020-12-02

Technologies: CefSharp.Wpf.HwndHost (NuGet), Google Chromium V8, CefSharp.Common (NuGet), Google Chrome, Microsoft Edge, CefSharp.Wpf (NuGet), CefSharp.WinForms (NuGet). Vendors: NuGet, Google, Opera, Microsoft.

Executive brief

A type confusion vulnerability in the Google Chromium V8 engine allows a remote attacker to potentially execute arbitrary code or cause heap corruption via a crafted HTML page. The flaw was exploited in the wild prior to being patched and affects multiple Chromium-based browsers.

Affected products

  • Google Chrome prior to 86.0.4240.183
  • Google V8 Engine
  • Microsoft Edge
  • Opera Opera

Timeline

  • 2020-11-02: patched: Stable channel update for desktop released (86.0.4240.183)
  • 2021-11-03: disclosed: Published in NVD and added to CISA KEV catalog
  • 2021-11-03: kev added

Related threats