CVE-2020-15971 is a use-after-free vulnerability in Google Chrome's printing component, affecting versions prior to 86.0.4240.75, as well as Debian, Fedora, and OpenSUSE. This high-severity vulnerability (CVSS 8.8) allows a remote attacker to potentially achieve a sandbox escape by compromising the renderer process and tricking a user into visiting a crafted HTML page. While the EPSS score is low and it's not in the KEV catalog, its FAUCET Risk Score is 71/100. There is no public exploit code (Metasploit, Nuclei, ExploitDB) and it is not currently being actively exploited, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 86.0.4240.75CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:a:opensuse:backports_sle:15.0:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.