Vulnerability record · CVE-2020-16013 · published 8 January 2021
CVE-2020-16013: Google Chrome V8 out-of-bounds write via crafted HTML page
Google · Chrome
Google Chrome before 86.0.4240.198 contains an inappropriate implementation in the V8 JavaScript engine that can lead to heap corruption. A remote attacker can trigger the flaw with a crafted HTML page, and the issue is listed in CISA's Known Exploited Vulnerabilities catalog, so it has seen real-world exploitation.
Description
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is remotely reachable, rated CVSS 8.8, and confirmed exploited in CISA KEV, though it requires user interaction and a patch has long been available.
What it is
Google Chrome before 86.0.4240.198 contains an inappropriate implementation in the V8 JavaScript engine that can lead to heap corruption. A remote attacker can trigger the flaw with a crafted HTML page, and the issue is listed in CISA's Known Exploited Vulnerabilities catalog, so it has seen real-world exploitation.
Impact
Successful exploitation can corrupt the heap and potentially allow arbitrary code execution in the browser process context. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
The flaw is reached over the network by rendering a crafted HTML page, so no authentication is required, but the victim must interact with the page (UI:R).
Exploitation
CVE-2020-16013 is in CISA KEV with a 2021-11-03 addition date, confirming known exploitation; EPSS 30-day probability is about 2.75 percent (85th percentile). No ransomware campaign use is documented.
What to do
- Update Google Chrome to 86.0.4240.198 or later, or apply the vendor's current stable channel release.
- Track the Chrome release notes and crbug.com/1147206 for the fixed build and any backports.
- Enforce automatic browser updates and verify version compliance across managed endpoints.
- Restrict or isolate untrusted web content through browser isolation or strict content policies where feasible.
Detection
- Monitor for Chrome processes spawning unexpected child processes or making anomalous network connections after browsing.
- Hunt for crashes or heap corruption indicators in Chrome/V8 telemetry that cluster around a single page or origin.
- Check endpoint inventories for Chrome versions below 86.0.4240.198 and flag them for immediate update.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-16013 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Google Chromium V8 Incorrect Implementation Vulnerabililty". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop_11.html | Release NotesVendor Advisory |
| https://crbug.com/1147206 | Permissions RequiredVendor Advisory |
| https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop_11.html | Release NotesVendor Advisory |
| https://crbug.com/1147206 | Permissions RequiredVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-16013 | US Government Resource |
Track CVE-2020-16013 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-16013), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.