CRITICAL
CVE-2020-16010
CVSS
9.6
KEV
Description
Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Summary dbcve.org
Heap buffer overflow vulnerability in the UI component of Google Chrome on Android before version 86.0.4240.185 allows a remote attacker who has already compromised the renderer process to potentially escape the sandbox via a crafted HTML page.
Mitigation
Update Google Chrome for Android to version 86.0.4240.185 or later to apply the vendor patch.
Weakness (CWE)
CWE-787
Out-of-bounds Write
CWE-122
Heap-based Buffer Overflow
EPSS Score
6.36%
Probability of exploitation in next 30 days
93.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.