Input validation error in Google Chrome - CVE-2020-16040
Published: December 2, 2020 / Updated: March 7, 2023
Vulnerability identifier: #VU48786
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-16040
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper input validation in V8 in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the system.
Affected software
Google Chrome
Gentoo Linux
Arch Linux
Fedora
chromium (Debian package)
chromium
Gentoo Linux
Arch Linux
Fedora
chromium (Debian package)
chromium
How to mitigate CVE-2020-16040
Update to version 87.0.4280.88.
Google Chrome - update to 87.0.4280.88
chromium (Debian package) - update to 87.0.4280.88-0.4~deb10u1
chromium - addressed in versions 87.0.4280.88-1.el7, 87.0.4280.88-1.el8, 87.0.4280.88-1.fc32, 87.0.4280.88-1.fc33
chromium (Debian package) - update to 87.0.4280.88-0.4~deb10u1
chromium - addressed in versions 87.0.4280.88-1.el7, 87.0.4280.88-1.el8, 87.0.4280.88-1.fc32, 87.0.4280.88-1.fc33