CVE-2020-16014: Use after free in PPAPI
Use after free in PPAPI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-16018
- CVE-2020-16019
- CVE-2020-16020
- CVE-2020-16021
- CVE-2020-16022
- CVE-2020-16015
- CVE-2020-16023
- CVE-2020-16024
- CVE-2020-16025
- CVE-2020-16045
- CVE-2020-16026
- CVE-2020-16027
- CVE-2020-16028
- CVE-2020-16029
- CVE-2020-16030
- CVE-2019-8075
- CVE-2020-16031
- CVE-2020-16032
- CVE-2020-16033
- CVE-2020-16034
- CVE-2020-16035
- CVE-2020-16012
- CVE-2020-16036
Frequently Asked Questions
What is the severity of CVE-2020-16014?
CVE-2020-16014 is considered a high severity vulnerability due to its potential for sandbox escape.
How can I fix CVE-2020-16014?
To fix CVE-2020-16014, upgrade your Google Chrome or Chromium browser to version 87.0.4280.66 or later.
What does CVE-2020-16014 exploit?
CVE-2020-16014 exploits a use after free vulnerability in the PPAPI component of Google Chrome.
On which platforms does CVE-2020-16014 affect Google Chrome?
CVE-2020-16014 affects Google Chrome on all supported desktop platforms prior to version 87.0.4280.66.
What impact can CVE-2020-16014 have on users?
CVE-2020-16014 can allow an attacker to escape the browser's sandbox and potentially execute arbitrary code on the user's system.