CVE-2020-16035: Insufficient data validation in cros-disks
Insufficient data validation in cros-disks in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass noexec restrictions via a malicious file.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-16018
- CVE-2020-16019
- CVE-2020-16020
- CVE-2020-16021
- CVE-2020-16022
- CVE-2020-16015
- CVE-2020-16014
- CVE-2020-16023
- CVE-2020-16024
- CVE-2020-16025
- CVE-2020-16045
- CVE-2020-16026
- CVE-2020-16027
- CVE-2020-16028
- CVE-2020-16029
- CVE-2020-16030
- CVE-2019-8075
- CVE-2020-16031
- CVE-2020-16032
- CVE-2020-16033
- CVE-2020-16034
- CVE-2020-16012
- CVE-2020-16036
Frequently Asked Questions
What is CVE-2020-16035?
CVE-2020-16035 is a vulnerability in cros-disks in Google Chrome on ChromeOS prior to version 87.0.4280.66, which allowed a remote attacker to bypass noexec restrictions via a malicious file.
What is the severity of CVE-2020-16035?
CVE-2020-16035 has a severity level of high.
How can an attacker exploit CVE-2020-16035?
An attacker can exploit CVE-2020-16035 by compromising the browser process and bypassing noexec restrictions through a malicious file.
Which versions of Google Chrome are affected by CVE-2020-16035?
Google Chrome versions prior to 87.0.4280.66 are affected by CVE-2020-16035.
How can CVE-2020-16035 be fixed?
To fix CVE-2020-16035, update Google Chrome to version 87.0.4280.66 or later.