Security News > 2020 > November > 2 More Google Chrome Zero-Days Under Active Exploitation

2 More Google Chrome Zero-Days Under Active Exploitation
2020-11-12 14:10

Google is asking Chrome desktop users to prepare to update their browsers once again as two more zero-day vulnerabilities have been identified in the software.

CVE-2020-16017 is described by Google as a "Use-after-free in site isolation," which is the Chrome component that isolates the data of different sites from each other.

The latest spate of Chrome zero-day discoveries and patches started on Oct. 19, when security researcher Sergei Glazunov of Google Project Zero discovered a type of memory-corruption flaw called a heap-buffer overflow in FreeType that was being actively exploited.

Google patched two separate zero-day flaws in Google's Chrome desktop and Android-based browsers.

The desktop bug is the aforementioned V8 vulnerability, which could be used for remote code-execution discovered by researchers at Google's Threat Analysis Group and Google Project Zero.


News URL

https://threatpost.com/2-zero-day-bugs-google-chrome/161160/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2021-01-08 CVE-2020-16017 Use After Free vulnerability in Google Chrome
Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
network
low complexity
google CWE-416
critical
9.6

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 102 253 4216 4506 727 9702