CVE-2020-16013: Inappropriate implementation in V8
Google Chromium V8 Engine contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Other sources
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 90.0.4430.212-1~deb10u1Fixed in 116.0.5845.180-1~deb11u1Fixed in 120.0.6099.129-1~deb11u1Fixed in 119.0.6045.199-1~deb12u1Fixed in 120.0.6099.129-1~deb12u1Fixed in 120.0.6099.129-1 - Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 86.0.4240.198
Event History
Frequently Asked Questions
What is CVE-2020-16013?
CVE-2020-16013 is a vulnerability in the Google Chromium V8 Engine that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.
How does CVE-2020-16013 affect Google Chrome?
CVE-2020-16013 affects Google Chrome versions up to 86.0.4240.198.
Is CVE-2020-16013 a high severity vulnerability?
Yes, CVE-2020-16013 has a severity rating of 8.8 (high).
What is the recommended remedy for CVE-2020-16013 on Debian?
The recommended remedy for CVE-2020-16013 on Debian is to update the 'chromium' package to one of the specified versions depending on the Debian release.
Where can I find more information about CVE-2020-16013?
More information about CVE-2020-16013 can be found in the references provided: 'https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop_11.html', 'https://crbug.com/1147206', and 'https://security-tracker.debian.org/tracker/CVE-2020-16013'.