CVE-2020-16042 is an Uninitialized Use vulnerability in Google Chrome's V8 JavaScript engine, affecting versions prior to 87.0.4280.88. A remote attacker could exploit this by tricking a user into visiting a crafted HTML page, leading to the disclosure of potentially sensitive information from process memory. This medium-severity vulnerability has a CVSS score of 6.5, indicating high confidentiality impact with no integrity or availability impact, and requires user interaction. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it garnered significant community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 87.0.4280.88CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.