ZeroHour

CVE-2020-16017

KEVmass

Use-After-Free Sandbox Escape in Google Chrome

CISA: Google Chrome Use-After-Free Vulnerability

CVSS 3.1
9.6 critical
EPSS
3%p85
Published
()
KEV added
AI analysis

CVE-2020-16017 is a use-after-free vulnerability in the site isolation component of Google Chrome, fixed in version 86.0.4240.198. It is triggered by a crafted HTML page and requires the attacker to have already compromised the renderer process, for example via a chained renderer bug. By exploiting the flaw, the attacker can escape Chrome's renderer sandbox and gain code execution with broader privileges on the host system. Any user running an affected Chrome release prior to 86.0.4240.198 is exposed. The flaw was a zero-day exploited in active attacks at the time of disclosure, is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), and Google shipped the fix as an urgent stable-channel update.

What to do: Update Google Chrome to version 86.0.4240.198 or later and verify the installed version in the browser's About dialog; enable automatic updates so renderer/sandbox fixes are applied promptly. Administrators should audit managed endpoints for outdated Chrome builds and prioritize updates given the confirmed in-the-wild exploitation and KEV listing; the required action per CISA is to apply updates per vendor instructions.

Affected
google chromeall versions prior to 86.0.4240.198
Estimated exposure
masson the order of a billion or more Chrome users (unpatched installs at disclosure; currently, mainly outdated/frozen Chrome installs) — Chrome is the world's dominant browser with a global user base of roughly 2-3 billion, so any flaw affecting all releases prior to the 86.0.4240.198 fix plausibly touches at least a billion users, with residual exposure concentrated on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chrome
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news