CVE-2020-16004 is a use-after-free vulnerability in Google Chrome's user interface, affecting Debian, Fedora, Google, and OpenSUSE products. A remote attacker could exploit this flaw via a crafted HTML page to potentially cause heap corruption. With a CVSS score of 8.8 (High), it presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. This vulnerability was actively exploited as a zero-day, as indicated by media coverage, despite a lack of public exploit code or Metasploit/Nuclei modules. It garnered notable community discussion and media attention, suggesting its importance to security professionals.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 86.0.4240.183CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:a:opensuse:backports_sle:15.0:sp2:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* | ||
15.2CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.