Input validation error in Google Chrome - CVE-2020-16007
Published: November 2, 2020 / Updated: November 3, 2020
Vulnerability identifier: #VU48095
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-16007
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper input validation in installer in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the system.
Affected software
Google Chrome
Arch Linux
SUSE Linux
Opensuse
chromium (Debian package)
Arch Linux
SUSE Linux
Opensuse
chromium (Debian package)
How to mitigate CVE-2020-16007
Update to version 86.0.4240.183.
Google Chrome - update to 86.0.4240.183
chromium (Debian package) - update to 87.0.4280.88-0.4~deb10u1
chromium (Debian package) - update to 87.0.4280.88-0.4~deb10u1