ZeroHour

CVE-2020-16009

KEV PoC ×2mass

Type Confusion in Google Chromium V8 Engine Enables RCE via Crafted HTML Pages

CISA: Google Chromium V8 Type Confusion Vulnerability

CVSS 3.1
8.8 high
EPSS
48%p99
Published
()
KEV added
AI analysis

CVE-2020-16009 is a type confusion vulnerability (CWE-843) in the V8 JavaScript engine used by Google Chromium, which can lead to heap corruption (CWE-787). A remote attacker triggers it by getting a user to load a specially crafted HTML page, such as via a malicious or compromised website. Successful exploitation corrupts the heap and can potentially allow the attacker to execute code in the context of the affected browser. Any Chromium-based browser or application embedding V8 is affected, including Google Chrome, Microsoft Edge, and Opera, meaning the affected population is effectively the entire Chromium user base worldwide. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-11-03, confirming exploitation in the wild, with an EPSS probability of 48.3% (99th percentile); ransomware use is unknown and no public PoC is known.

What to do: Apply the vendor update per CISA's required action: update all Chromium-based browsers (Chrome, Edge, Opera, and derivatives) to the latest stable releases from each vendor and restart browsers afterward. Inventory any embedded or packaged Chromium/V8 runtimes in other applications and update them as their maintainers ship fixes. Given confirmed in-the-wild exploitation and high EPSS, prioritize patching endpoints used for web browsing by high-risk users first.

Affected
Google Chromium V8
Google Chrome (Chromium-based browser)
Microsoft Edge (Chromium-based browser)
Opera (Chromium-based browser)
Estimated exposure
mass≈3+ billion browser users/installations (Chromium is the world's dominant browser engine) — Chromium's V8 engine underpins Google Chrome, Microsoft Edge, Opera and many other mainstream browsers that together account for the large majority of global web browsing, so the exposed population is estimated at billions of users; exact…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cefsharpgooglemicrosoftopensusefedoraprojectdebian
Products
cefsharp, chrome, edge, edge chromium, backports sle, leap, fedora, debian linux
Weakness
CWE-787, CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news