EXPOSURES › CVE-2020-6572
CVE-2020-6572
HIGH ⌖ ON CISA KEV · EXPLOITEDA use-after-free vulnerability in Google Chrome's media component allowed remote code execution via a crafted HTML page and was actively exploited in the wild.
This use-after-free flaw in Chrome's media stack enabled attackers to execute arbitrary code remotely by tricking users into visiting a malicious webpage. DIB organizations must ensure their browsers are patched immediately, as this vulnerability was actively exploited in the wild and represents a significant compliance risk under NIST 800-171 for unpatched software.
Shame score — The vulnerability was actively exploited in the wild, indicating a failure to patch known critical flaws before they were weaponized by attackers.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page.
| PRODUCT | STATUS |
|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) Google |
Authorized |
| Google Workspace Google |
Authorized |