CVE-2020-16040 is a heap corruption vulnerability in Google Chrome's V8 JavaScript engine, affecting versions prior to 87.0.4280.88 due to insufficient data validation. This medium-severity vulnerability (CVSS 6.5) can be exploited by a remote attacker via a crafted HTML page, potentially leading to a denial of service or arbitrary code execution. While not on CISA's KEV catalog, exploit code is publicly available, including a Metasploit module and an ExploitDB entry, indicating a high likelihood of exploitation. The vulnerability has garnered significant community attention and media coverage, highlighting its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 87.0.4280.88CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.