← back
CVE-2020-16040observed exploitation

CVE-2020-16040

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 100%
from disclosure to weapon88 days
Published on NVDJan 8
1st PoC+88d
metasploitNov 19
VulnCheck+1844d
exploitation probability
100%top 1% of all CVEs
observed exploitation
yesVulnCheck
5 public exploit(s)
In short

Google Chrome's V8 engine didn't properly check data before processing it, allowing attackers to corrupt the computer's memory by tricking users into visiting a malicious website.

Technical detail

Insufficient input validation in V8 allowed remote code execution through heap corruption via crafted HTML. Attack vector is web-based (malicious webpage), requires user interaction (visiting the site), and can lead to arbitrary code execution with Chrome process privileges.

Summary generated and translated by AI from the official description.
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected products
Google · Chrome
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.