ZeroHour

CVE-2020-16013

KEVmass

Heap Corruption in Google Chrome V8 Engine (CVE-2020-16013) Under Active Attack

CISA: Google Chromium V8 Incorrect Implementation Vulnerabililty

CVSS 3.1
8.8 high
EPSS
3%p85
Published
()
KEV added
AI analysis

Google Chrome's V8 JavaScript engine contained an inappropriate implementation (CWE-787, out-of-bounds write) that could corrupt the browser's heap. A remote attacker triggers the flaw by getting a user to open a crafted HTML page, since the bug is reached through JavaScript processing in the browser (user interaction is required, per the CVSS vector). Successful exploitation could allow the attacker to execute code in the browser with high confidentiality, integrity and availability impact, consistent with the 8.8 CVSS score. All Google Chrome users running versions prior to 86.0.4240.198 were affected, as are Chromium-based builds relying on the same V8 code. The flaw was a zero-day under active attack when Google patched it in the November 2020 stable-channel update; it was added to CISA KEV on 2021-11-03 (ransomware use unknown), carries a 2.8% EPSS (85th percentile), and no public PoC is known.

What to do: Upgrade Google Chrome to 86.0.4240.198 or later on all endpoints and verify the running version at chrome://version; this is the November 2020 stable-channel release that patched the actively exploited zero-day. Chromium-based browsers (e.g., Edge, Brave, Opera, Vivaldi) inherit the V8 fix through their own upstream updates, so ensure the latest available release is deployed there as well. As a CISA KEV entry, the required action is to apply vendor updates per vendor instructions within the KEV patching deadline.

Affected
google chromeall versions prior to 86.0.4240.198 (fixed in 86.0.4240.198)
google chromium v8 (javascript engine)V8 as bundled in Chrome/Chromium prior to 86.0.4240.198
Estimated exposure
massbillions of users/installations (Chrome is the world's dominant browser, roughly two-thirds desktop market share) — Estimated from Chrome's global installed base — the most widely used browser at roughly 65-70% desktop market share — since every version below 86.0.4240.198 was vulnerable at disclosure.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
google
Products
chrome
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news