Executive brief
A heap buffer overflow vulnerability exists in the UI component of Google Chrome for Android. A remote attacker who has already compromised the renderer process can exploit this flaw via a crafted HTML page to perform a sandbox escape.
Affected products
- Google Chrome prior to 86.0.4240.185
Timeline
- 2020-11-02: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2020-11-02: exploited: Reported as exploited in the wild at time of disclosure