EXPOSURES › CVE-2020-15999
CVE-2020-15999
HIGH ⌖ ON CISA KEV · EXPLOITEDA heap buffer overflow in Google Chrome's FreeType font rendering library was actively exploited in the wild as part of an exploit chain.
The vulnerability allowed remote code execution via malicious PNG images embedded in fonts, which was part of a known exploit chain targeting Windows and Android. DIB organizations must ensure their browsers are patched and monitor for supply-chain compromises in open-source libraries like FreeType. This is not a zero-day as it was part of an active exploit chain.
Shame score — The vulnerability was actively exploited in the wild as part of an exploit chain, indicating a failure to patch a known issue before it was weaponized.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.
| PRODUCT | STATUS |
|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) Google |
Authorized |
| Google Workspace Google |
Authorized |