Chrome 86.0.4240.111 fixes actively exploited CVE-2020-15999 zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-13720 | Use-After-Free in Google Chrome WebAudio Allows Heap Corruption (Actively Exploited) CVE-2019-13720 is a use-after-free (CWE-416) in the WebAudio component of Google Chrome that exists in all releases prior to 78.0.3904.87. A remote attacker can trigger the flaw by luring a user to a crafted HTML page, corrupting the heap when the browser processes audio through the freed memory. Successful exploitation can lead to remote code execution with high impact on confidentiality, integrity, and availability, and a public proof-of-concept for Chrome 78.0.3904.70 is available. The flaw affects desktop and mobile users running vulnerable Chrome builds as well as the Chromium package shipped for openSUSE Leap. Exploitation is confirmed in the wild: Google fixed it as an actively exploited issue in November 2019, it was used in the Operation WizardOpium attacks, and it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-23. Do: Upgrade Google Chrome to 78.0.3904.87 or later (check the current version via the browser's About/Help page) and update the Chromium package on openSUSE Leap using the distribution's update channels. Because this flaw is triggered via a crafted web page and there are no reliable configuration workarounds, prioritizing browser patching across all endpoints is the key mitigation. Defenders should also review whether any user activity coincided with the Operation WizardOpium campaign, as this bug was chained in active attacks. | 8.8 | 73% | KEV PoC |
| masshundreds of millions to billions of Chrome installations worldwide (Chrome is the dominant web browser) | |
| CVE-2020-15999 | Heap Buffer Overflow in FreeType Font Rendering in Google Chrome (CVE-2020-15999) Google Chrome bundles the open-source FreeType library for font rendering, and that library contains a heap buffer overflow (CWE-787, out-of-bounds write) in its Load_SBit_Png function. The flaw is triggered when the browser loads a crafted font containing a malicious PNG image embedded as embedded bitmap data, typically from a web page the victim visits, corrupting heap memory with attacker-controlled data. Successful exploitation can crash the browser or execute code in the renderer, and it was used in the wild as part of an exploit chain combined with CVE-2020-17087 (Windows kernel) and CVE-2020-16010 (Android) to escape the sandbox. Anyone running an affected Google Chrome release that ships the vulnerable FreeType code, across Windows, macOS, Linux, Chrome OS and Android, is affected, meaning effectively the entire Chrome install base at the time of disclosure. The vulnerability is confirmed exploited in the wild (listed in CISA's KEV catalog, added 2021-11-03; ransomware use unknown), Google patched it in Chrome 86.0.4240.111, no public proof-of-concept is known, and EPSS estimates a 44.3% probability of exploitation within 30 days (99th percentile). Do: Update Google Chrome to 86.0.4240.111 or later (any current stable-channel release satisfies this), and where other software bundles FreeType directly, update to FreeType 2.10.4 or later per the upstream fix. Because the bug was chained with CVE-2020-17087 on Windows and CVE-2020-16010 on Android, also apply the corresponding Microsoft Windows and Android updates to close the sandbox-escape chain. Use endpoint management to inventory browser versions and confirm no endpoints remain below the fixed release, as required by the CISA KEV catalog. | 9.6 | 44% | KEV PoC ×2 |
| masson the order of billions of users (Chrome's active user base exceeded ~3 billion at the time; the vulnerable FreeType code shipped in every affected release) | |
| CVE-2020-6418 | Type Confusion in Google Chrome's V8 Engine Enables Heap Corruption CVE-2020-6418 is a type confusion vulnerability (CWE-843) in V8, the JavaScript engine used in Google Chrome and Chromium, affecting versions prior to 80.0.3987.122. A remote attacker triggers it by persuading a user to open a crafted HTML page whose JavaScript causes V8 to mishandle object types (public PoCs reference a JSCreate side-effect issue), potentially leading to heap corruption. Successful exploitation can yield arbitrary code execution in the browser, a common stepping stone for further compromise on the victim's system. Any Chrome/Chromium deployment with the vulnerable V8 was affected, including Chromium packages shipped by Fedora, Red Hat Enterprise Linux, and Debian. The flaw was a zero-day exploited in the wild when patched in February 2020; it is listed in CISA KEV (added 2021-11-03) and carries a very high EPSS of 78.8%, making it a priority patch. Do: Update Google Chrome to 80.0.3987.122 or later and confirm the running version via chrome://settings/help or chrome://version. Apply the updated Chromium packages from Fedora, Red Hat, and Debian on managed Linux endpoints and check whether any hosts still run pre-fix Chromium. Given the KEV listing and 78.8% EPSS, treat patching as urgent; as an interim mitigation on unpatched systems, limit untrusted web browsing or restrict JavaScript from untrusted sites. | 8.8 | 79% | KEV PoC ×2 |
| massbillions of users/installations (Chrome's global install base runs to billions, and at disclosure in February 2020 every Chrome user on a pre-80.0.3987.122… |
Full article224 words · extracted from securityaffairs.com · click to collapse

Google has released Chrome version 86.0.4240.111 that also addresses the CVE-2020-15999 flaw which is an actively exploited zero-day.
Google has released Chrome version 86.0.4240.111 that includes security fixes for several issues, including a patch for an actively exploited zero-day vulnerability tracked as CVE-2020-15999.
The CVE-2020-15999 flaw is a memory corruption bug that resides in the FreeType font rendering library, which is included in standard Chrome releases.
White hat hackers from the Google Project Zero team spotted attacks exploiting the vulnerability in the wild.
The researchers did not disclose technical details about the attacks exploiting the CVE-2020-15999 in the wild to avoid mass exploitation from threat actors.
Google Project Zero is recommending other app development teams who use the same FreeType library to update their software as well.
The FreeType version 2.10.4 address this issue.
Chrome users can update their install to v86.0.4240.111 via the browser’s built-in update function.
Experts pointed out that since the patch for this zero-day is visible in the source code of the FreeType open-source library, threat actors will be able to make a reverse-engineering of the code and develop working exploits for the issue.
In the recent twelve months, Google addressed another two zero-day vulnerabilities tracked as CVE-2019-13720 (Oct. 2019) and CVE-2020-6418 (Feb. 2020) respectively
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Chrome)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/109823/hacking/chrome-cve-2020-15999-zero-day.html