Junglewise Threat Intelligence

CVE-2020-16010: Google Chrome for Android UI Heap Buffer Overflow Vulnerability

CVE-2020-16010 · Severity: critical · CVSS 9.6 · Exploited in the wild · Published 2021-11-03

Technologies: Google Chrome. Vendors: Google.

Executive brief

A heap buffer overflow vulnerability exists in the UI component of Google Chrome for Android. A remote attacker who has already compromised the renderer process can exploit this flaw via a crafted HTML page to perform a sandbox escape.

Affected products

  • Google Chrome prior to 86.0.4240.185

Timeline

  • 2020-11-02: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2020-11-02: exploited: Reported as exploited in the wild at time of disclosure