FlawAtlas
Search the atlas
CVE-2020-16009 High

Confirmed as exploited

CVE-2020-16009

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Exploit probability 48.6%
Published November 3, 2020
Required by May 3, 2022
Last source change July 8, 2026

01 / ACTION

Required action

Apply updates per vendor instructions.

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

34 explicit affected versions

NuGet CefSharp.Common

87 explicit affected versions

NuGet CefSharp.WinForms

86 explicit affected versions

NuGet CefSharp.Wpf

94 explicit affected versions

NuGet CefSharp.Wpf.HwndHost

4 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2024:10681-1
related OPENSUSE-SU-2024:12948-1

04 / EVIDENCE

Source records

Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities CVE-2020-16009

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

View original source
Open Source Vulnerabilities CVE-2020-16009

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

View original source
Open Source Vulnerabilities GHSA-m7mf-48hp-5qmr

CVE-2020-16009: Inappropriate implementation in V8 - https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop.html - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16009 Google is aware of reports that exploits for CVE-2020-16009 exist in the wild. Allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. There is currently little to no public information on the issue other than it has been flagged as `High` severity.

View original source

05 / REFERENCES

Further evidence