Skip to content

Inappropriate implementation in V8 (CVE-2020-16009)

High
amaitland published GHSA-m7mf-48hp-5qmr Dec 1, 2020

Package

nuget CefSharp.Common, CefSharp.Wpf, CefSharp.WinForms, CefSharp.Wpf, CefSharp.Wpf.HwndHost (Nuget)

Affected versions

< 86.0.241

Patched versions

86.0.241

Description

CVE-2020-16009: Inappropriate implementation in V8

Google is aware of reports that exploits for CVE-2020-16009 exist in the wild.

Allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

There is currently little to no public information on the issue other than it has been flagged as High severity.

Severity

High

CVE ID

CVE-2020-16009

Weaknesses

No CWEs