CVE-2020-16009 is a critical heap corruption vulnerability in Google Chrome's V8 JavaScript engine, affecting versions prior to 86.0.4240.183, as well as products like CefSharp, Debian, and Microsoft Edge. With a CVSS score of 8.8 (HIGH), it allows remote attackers to achieve high impact on confidentiality, integrity, and availability through a crafted HTML page, requiring user interaction. This vulnerability is actively exploited in the wild, as confirmed by its presence in the KEV catalog and extensive media coverage, despite no public exploit code being available on platforms like Metasploit or ExploitDB. Community discussion indicates significant interest in understanding and finding exploit code for this zero-day.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 86.0.241CPE matchmatch criteria | cpe:2.3:a:cefsharp:cefsharp:*:*:*:*:*:*:*:* | ||
< 86.0.4240.183CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 86.0.622.63CPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* | ||
< 86.0.4240.183CPE matchmatch criteria | cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.