CVE-2020-16010 is a critical heap buffer overflow vulnerability in the UI component of Google Chrome on Android, affecting versions prior to 86.0.4240.185. This flaw allows a remote attacker, after compromising the renderer process, to achieve a sandbox escape via a specially crafted HTML page. With a CVSS score of 9.6 (CRITICAL), it presents a high risk due to its network-based attack vector, low attack complexity, and high potential for confidentiality, integrity, and availability impacts. The vulnerability is listed in CISA's KEV catalog, indicating active exploitation in the wild, and has garnered significant community discussion and media coverage, despite no public exploit code being readily available through common exploit databases.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 86.0.4240.185CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.