FlawAtlas
Search the atlas
CVE-2020-15999 Critical

Confirmed as exploited

CVE-2020-15999

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Exploit probability 50.6%
Published November 3, 2020
Required by November 17, 2021
Last source change August 7, 2026

01 / ACTION

Required action

Apply updates per vendor instructions.

02 / AFFECTED SOFTWARE

Affected packages

Android platform/external/freetype

5 explicit affected versions

Unknown Unknown

104 explicit affected versions

NuGet CefSharp.Common

85 explicit affected versions

NuGet CefSharp.WinForms

84 explicit affected versions

NuGet CefSharp.Wpf

92 explicit affected versions

NuGet CefSharp.Wpf.HwndHost

3 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2024:10681-1
related OPENSUSE-SU-2024:12948-1
related OPENSUSE-SU-2024:14572-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities ASB-A-171232105

In Load_SBit_Png of pngshim.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.

View original source
Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities CVE-2020-15999

Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.

View original source
Open Source Vulnerabilities GHSA-pv36-h7jh-qm62

### Impact A memory corruption bug(Heap overflow) in the FreeType font rendering library. > This can be exploited by attackers to execute arbitrary code by using specially crafted fonts with embedded PNG images . As per https://www.secpod.com/blog/chrome-zero-day-under-active-exploitation-patch-now/ Google is aware of reports that an exploit for CVE-2020-15999 exists in the wild. ### Patches Upgrade to 85.3.130 or higher ### References - https://www.secpod.com/blog/chrome-zero-day-under-active-exploitation-patch-now/ - https://www.zdnet.com/article/google-releases-chrome-security-update-to-patch-actively-exploited-zero-day/ - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15999 - https://magpcss.org/ceforum/viewtopic.php?f=10&t=17942 To review the `CEF/Chromium` patch see https://bitbucket.org/chromiumembedded/cef/commits/cd6cbe008b127990036945fb75e7c2c1594ab10d

View original source
Open Source Vulnerabilities CVE-2020-15999

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

View original source

05 / REFERENCES

Further evidence