Junglewise Threat Intelligence

CVE-2020-6572: Google Chrome Media Use-After-Free Vulnerability

CVE-2020-6572 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-01-10

Technologies: Google Chrome. Vendors: Google.

Executive brief

A use-after-free vulnerability in the Media component of Google Chrome allows a remote attacker to execute arbitrary code. The exploit is triggered when a user visits a specially crafted HTML page.

Affected products

  • Google Chrome prior to 81.0.4044.92

Timeline

  • 2020-04-07: patched: Fixed in Chrome version 81.0.4044.92
  • 2021-01-14: disclosed: NVD Published Date
  • 2022-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog