Skip to content
COOEY

EXPOSURES › CVE-2020-16010

CVE-2020-16010

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-16010 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatched

A heap buffer overflow in Chrome for Android UI allowed sandbox escapes after a renderer compromise, but lacked RCE and zero-day status.

The vulnerability required an initial compromise of the renderer process before a crafted HTML page could trigger a sandbox escape, limiting its direct exploitability. DIB organizations should care because it highlights the risk of relying on browser sandboxing without additional hardening, and the fact it was in KEV indicates active exploitation attempts. Organizations should ensure their Chrome versions are patched and consider additional browser hardening measures.

Shame score — The vulnerability was actively exploited (KEV) but required an initial compromise, and was not a zero-day; however, its presence in KEV and potential for sandbox escapes warrant moderate embarrassment.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chrome for Android UI contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
cooey ↗ severe-fallout -0.70
"…"
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized