EXPOSURES › CVE-2020-16010
CVE-2020-16010
HIGH ⌖ ON CISA KEV · EXPLOITEDA heap buffer overflow in Chrome for Android UI allowed sandbox escapes after a renderer compromise, but lacked RCE and zero-day status.
The vulnerability required an initial compromise of the renderer process before a crafted HTML page could trigger a sandbox escape, limiting its direct exploitability. DIB organizations should care because it highlights the risk of relying on browser sandboxing without additional hardening, and the fact it was in KEV indicates active exploitation attempts. Organizations should ensure their Chrome versions are patched and consider additional browser hardening measures.
Shame score — The vulnerability was actively exploited (KEV) but required an initial compromise, and was not a zero-day; however, its presence in KEV and potential for sandbox escapes warrant moderate embarrassment.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chrome for Android UI contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page.
| PRODUCT | STATUS |
|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) Google |
Authorized |
| Google Workspace Google |
Authorized |