Out-of-bounds write in Google Chrome for Android - CVE-2020-15995

 

Out-of-bounds write in Google Chrome for Android - CVE-2020-15995

Published: October 20, 2020 / Updated: June 11, 2021


Vulnerability identifier: #VU47725
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-15995
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input in V8. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger out-of-bounds write and execute arbitrary code on the target system.


Affected software

Google Chrome for Android
Gentoo Linux
Arch Linux
Fedora
chromium (Debian package)
chromium
Google Chrome

How to mitigate CVE-2020-15995

Install updates from vendor's website.

Google Chrome for Android - update to 86.0.4240.99
chromium (Debian package) - update to 87.0.4280.141-0.1~deb10u1
Google Chrome - update to 87.0.4280.141
chromium - addressed in versions 87.0.4280.141-1.el7, 87.0.4280.141-1.el8, 87.0.4280.141-1.fc32, 87.0.4280.141-1.fc33, 88.0.4324.96-1.el7, 88.0.4324.96-1.el8, 88.0.4324.150-1.el7, 88.0.4324.150-1.el8

External References

Related Security Bulletins