CVE-2020-16019 describes an inappropriate implementation vulnerability in the filesystem component of Google Chrome on ChromeOS, affecting versions prior to 87.0.4280.66. This flaw allowed a remote attacker, after compromising the browser process, to bypass noexec restrictions using a malicious file. Rated with a CVSS score of 8.8 (High), this vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation (not in KEV or Hot List), and no public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 87.0.4280.66CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.