ZeroHour

CVE-2020-6572

KEVmass

Use-After-Free RCE in Google Chrome Media Engine

CISA: Google Chrome Media Use-After-Free Vulnerability

CVSS 3.1
8.8 high
EPSS
11%p96
Published
()
KEV added
AI analysis

CVE-2020-6572 is a use-after-free (CWE-416) in the Media component of Google Chrome that allows a remote attacker to execute arbitrary code by persuading a user to open a crafted HTML page. The CVSS vector (AV:N/AC:L/PR:N/UI:R) shows the attack is network-delivered but requires user interaction, meaning a victim must load attacker-controlled web content for the memory corruption to occur. Successful exploitation yields high confidentiality, integrity, and availability impact — effectively remote code execution in the context of the browser. All Google Chrome versions prior to 81.0.4044.92 are affected, so the exposure is any Chrome install that has not applied that release or later. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-01-10), confirming exploitation in the wild, and EPSS assigns a 10.6% probability of exploitation in the next 30 days (96th percentile).

What to do: Update Google Chrome to 81.0.4044.92 or later — any currently maintained release satisfies this — and verify the running version at chrome://settings/help with auto-update enabled. Prioritize legacy or offline systems (old workstations, kiosks, VDI golden images) that may still run 2020-era Chrome, since the KEV listing (added 2022-01-10) makes remediation mandatory for federal agencies.

Affected
google chromeprior to 81.0.4044.92
Estimated exposure
massmillions of users on legacy pre-81.0.4044.92 Chrome installs (Chrome's installed base exceeds 3 billion) — Chrome holds roughly 65% browser market share with a 3+ billion user base, so even the small residual fraction of unmaintained installs still running 2020-era builds plausibly represents millions of users.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chrome Media
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.