Junglewise Threat Intelligence

CVE-2020-16013: Inappropriate implementation in V8 in CefSharp

CVE-2020-16013 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2020-11-27

Technologies: Google Chromium V8, CefSharp.Wpf (NuGet), CefSharp.Wpf.HwndHost (NuGet), Google Chrome, CefSharp.Common (NuGet), Microsoft Edge, CefSharp.WinForms (NuGet). Vendors: Google, NuGet, Opera, Microsoft.

Executive brief

Google Chromium V8 Engine contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability can lead to out-of-bounds writes and has been observed being exploited in the wild.

Affected products

  • Google Chrome prior to 86.0.4240.198
  • Google V8 Engine prior to 86.0.4240.198
  • Microsoft Edge
  • Opera Opera

Timeline

  • 2020-11-11: patched: Stable channel update for desktop released (86.0.4240.198)
  • 2021-01-08: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild

Related threats