CVE-2020-16009
Description
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
In plain language
AI Act nowCVE-2020-16009 is a browser bug where a bad website could crash or potentially take over older Chrome/Edge or apps that embed Chromium (via CefSharp); if you’re not fully updated, you should act now.
CVE-2020-16009 is a heap-corruption vulnerability in the V8 JavaScript engine in Google Chrome (and Chromium-based Edge) before 86.0.4240.183 that can be triggered by visiting a specially crafted HTML page; it has been listed in CISA KEV, indicating real-world exploitation, so updating is critical.
What to do now
- Check whether your affected browser/app is running a vulnerable version (Google Chrome or Microsoft Edge/Edge Chromium) or an embedded Chromium build via CefSharp.
- If you use Google Chrome, update it to 86.0.4240.183 or later.
- If you use Microsoft Edge or Edge Chromium, update it to 86.0.622.63 or later (or update to the Chrome-equivalent 86.0.4240.183 where applicable).
- If you use CefSharp, update CefSharp components to 86.0.241 or later (including CefSharp.Common and CefSharp.Wpf).
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2020-16009 and every CVE in our database. Create a free account — no credit card required.
Create Free Account