Junglewise Threat Intelligence

CVE-2020-16017: Use after free in CefSharp

CVE-2020-16017 · Severity: critical · CVSS 9.6 · Exploited in the wild · Published 2020-11-27

Technologies: CefSharp.Wpf.HwndHost (NuGet), Google Chrome, CefSharp.Common (NuGet), CefSharp.Wpf (NuGet), CefSharp.WinForms (NuGet). Vendors: NuGet, Google.

Executive brief

A use-after-free vulnerability in site isolation in Google Chrome allows a remote attacker who has already compromised the renderer process to perform a sandbox escape. Exploitation is achieved via a specially crafted HTML page and requires user interaction.

Affected products

  • Google Chrome < 86.0.4240.198

Timeline

  • 2021-01-08: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: advisory: CISA Advisory Publication

Related threats