First published: Tue Sep 29 2020(Updated: )
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit: chrome-cve-admin@google.com Bill Parks
Affected Software | Affected Version | How to fix |
---|---|---|
debian/chromium | 90.0.4430.212-1~deb10u1 116.0.5845.180-1~deb11u1 120.0.6099.129-1~deb11u1 119.0.6045.199-1~deb12u1 120.0.6099.129-1~deb12u1 120.0.6099.129-1 | |
Google Chrome | <86.0.4240.183 | |
openSUSE Backports SLE | =15.0-sp1 | |
openSUSE Backports SLE | =15.0-sp2 | |
Debian Debian Linux | =10.0 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 | |
openSUSE Leap | =15.1 | |
openSUSE Leap | =15.2 | |
Google Chrome | <86.0.4240.183 | 86.0.4240.183 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-16006 is a vulnerability in V8 in Google Chrome prior to version 86.0.4240.183 that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-16006 affects Google Chrome versions prior to 86.0.4240.183.
Google Chrome versions prior to 86.0.4240.183, openSUSE Backports SLE 15.0 (SP1 and SP2), Debian Debian Linux 10.0, Fedoraproject Fedora 32 and 33, openSUSE Leap 15.1 and 15.2.
CVE-2020-16006 has a severity rating of 8.8 (high).
You can find more information about CVE-2020-16006 at the following references: http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00016.html, http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00017.html, https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop.html