CVE-2020-16045: Use after free in Payments
Published Sep 7, 2020
·Updated
Use after Free in Payments in Google Chrome on Android prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Credit
Man Yue Mo(GitHub Security Lab)
Affected Software
3 affected componentsFixes available
Google Chrome<87.0.4280.66
87.0.4280.66
Google Chrome<87.0.4280.66
Google Android
Event History
Sep 7, 2020
CVE Published
12:00 AM
Jan 14, 2021
CVE Published
via MITRE·08:55 PM
Data Sourced
via MITRE·08:55 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-16018
- CVE-2020-16019
- CVE-2020-16020
- CVE-2020-16021
- CVE-2020-16022
- CVE-2020-16015
- CVE-2020-16014
- CVE-2020-16023
- CVE-2020-16024
- CVE-2020-16025
- CVE-2020-16026
- CVE-2020-16027
- CVE-2020-16028
- CVE-2020-16029
- CVE-2020-16030
- CVE-2019-8075
- CVE-2020-16031
- CVE-2020-16032
- CVE-2020-16033
- CVE-2020-16034
- CVE-2020-16035
- CVE-2020-16012
- CVE-2020-16036
Frequently Asked Questions
1
What is the severity of CVE-2020-16045?
CVE-2020-16045 is classified as a high-severity vulnerability.
2
How do I fix CVE-2020-16045?
To fix CVE-2020-16045, update Google Chrome to version 87.0.4280.66 or later.
3
What type of vulnerability is CVE-2020-16045?
CVE-2020-16045 is a use after free vulnerability in the Payments feature of Google Chrome on Android.
4
Who is affected by CVE-2020-16045?
Users of Google Chrome on Android versions prior to 87.0.4280.66 are affected by CVE-2020-16045.
5
Can CVE-2020-16045 lead to sandbox escape?
Yes, CVE-2020-16045 can potentially allow a remote attacker to perform a sandbox escape.