CVE-2020-16042: Uninitialized Use in V8
Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Other sources
When a BigInt was right-shifted the backing store was not properly cleared, allowing uninitialized memory to be read.
— Mozilla
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2020-16042?
CVE-2020-16042 is considered a medium severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2020-16042?
To fix CVE-2020-16042, update Google Chrome to version 87.0.4280.88 or later.
What software is affected by CVE-2020-16042?
CVE-2020-16042 affects Google Chrome versions prior to 87.0.4280.88 and specific versions of Chromium, Firefox, Firefox ESR, and Thunderbird.
What type of vulnerability is CVE-2020-16042?
CVE-2020-16042 is an uninitialized use vulnerability in the V8 JavaScript engine of Google Chrome.
What can an attacker achieve with CVE-2020-16042?
An attacker can potentially obtain sensitive information from process memory through a crafted HTML page with CVE-2020-16042.