GHSA-m7mf-48hp-5qmr
CVE-2020-16009: Inappropriate implementation in V8
- https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16009
Google is aware of reports that exploits for CVE-2020-16009 exist in the wild.
Allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
There is currently little to no public information on the issue other than it has been flagged as High severity.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/cefsharp/CefSharp/security/advisories/GHSA-m7mf-48hp-5qmr, https://nvd.nist.gov/vuln/detail/CVE-2020-16009, https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop.html, https://crbug.com/1143772, https://github.com/cefsharp/CefSharp, https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S4XYJ7B6OXHZNYSA5J3DBUOFEC6WCAGW, https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SC3U3H6AISVZB5PLZLLNF4HMQ4UFFL7M, https://security.gentoo.org/glsa/202011-12, https://www.debian.org/security/2021/dsa-4824, http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00016.html, http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00017.html, http://packetstormsecurity.com/files/159974/Chrome-V8-Turbofan-Type-Confusion.html
