CVE-2020-16017 is a critical use-after-free vulnerability in Google Chrome prior to version 86.0.4240.198, specifically affecting its site isolation feature. This flaw allows a remote attacker, after compromising the renderer process, to potentially escape the browser's sandbox by enticing a user to visit a specially crafted HTML page. With a CVSS score of 9.6 (CRITICAL), this vulnerability poses a significant risk, enabling complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, as indicated by its presence in the KEV catalog, and has garnered substantial community discussion and media coverage, despite no public exploit code being readily available in common frameworks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 86.0.4240.198CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.