CVE-2020-16012: channel information leakage in graphics
Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Other sources
When drawing a transparent image on top of an unknown cross-origin image, the Skia library drawImage function took a variable amount of time depending on the content of the underlying image. This resulted in potential cross-origin information exposure of image content through timing side-channel attacks.
Credit
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-26951
- CVE-2020-16012
- CVE-2020-26953
- CVE-2020-26956
- CVE-2020-26958
- CVE-2020-26959
- CVE-2020-26960
- CVE-2020-15999
- CVE-2020-26961
- CVE-2020-26965
- CVE-2020-26966
- CVE-2020-26968
- CVE-2020-26952
- CVE-2020-26954
- CVE-2020-26955
- CVE-2020-26957
- CVE-2020-26962
- CVE-2020-26963
- CVE-2020-26964
- CVE-2020-26967
- CVE-2020-26969
- CVE-2020-16018
- CVE-2020-16019
- CVE-2020-16020
- CVE-2020-16021
- CVE-2020-16022
- CVE-2020-16015
- CVE-2020-16014
- CVE-2020-16023
- CVE-2020-16024
- CVE-2020-16025
- CVE-2020-16045
- CVE-2020-16026
- CVE-2020-16027
- CVE-2020-16028
- CVE-2020-16029
- CVE-2020-16030
- CVE-2019-8075
- CVE-2020-16031
- CVE-2020-16032
- CVE-2020-16033
- CVE-2020-16034
- CVE-2020-16035
- CVE-2020-16036
Frequently Asked Questions
What is CVE-2020-16012?
CVE-2020-16012 is a vulnerability in Google Chrome and Mozilla Firefox that allowed remote attackers to potentially leak cross-origin information through a timing side-channel attack.
Which software versions are affected by CVE-2020-16012?
Google Chrome versions prior to 87.0.4280.66 and Mozilla Firefox versions up to 83.0 are affected by CVE-2020-16012.
How severe is CVE-2020-16012?
CVE-2020-16012 has a medium severity rating.
How can I fix CVE-2020-16012 in Google Chrome?
To fix CVE-2020-16012 in Google Chrome, update to version 87.0.4280.66 or later.
How can I fix CVE-2020-16012 in Mozilla Firefox?
To fix CVE-2020-16012 in Mozilla Firefox, update to version 83.0 or later.