Vulnerability record · CVE-2020-16017 · published 8 January 2021
CVE-2020-16017: Google Chrome site isolation use-after-free sandbox escape
Google · Chrome
Chrome before 86.0.4240.198 contains a use-after-free in site isolation. An attacker who already controls a renderer process can use a crafted HTML page to break out of the browser sandbox. Because it defeats the sandbox, it is a serious escalation primitive rather than a standalone initial-access bug.
Description
Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Automated analysis
high priorityIt is a KEV-listed sandbox escape with critical CVSS impact, but exploitation requires a prior renderer compromise and user interaction, lowering standalone risk.
What it is
Chrome before 86.0.4240.198 contains a use-after-free in site isolation. An attacker who already controls a renderer process can use a crafted HTML page to break out of the browser sandbox. Because it defeats the sandbox, it is a serious escalation primitive rather than a standalone initial-access bug.
Impact
An attacker with an existing renderer compromise gains code execution outside the sandbox, typically at the browser's privilege level, enabling access to user data and the host system.
Attack surface
Reached over the network via a crafted HTML page, requiring user interaction to load it. The attacker must first have compromised the renderer process, so this is a second-stage exploit, not an unauthenticated remote entry point.
Exploitation
Listed in CISA KEV with a 2022-05-03 remediation due date, indicating known exploitation. EPSS 30-day probability is about 2.7 percent (85th percentile), so mass scanning is not indicated, but targeted use is plausible.
What to do
- Update Chrome to 86.0.4240.198 or later, or the current stable release, on all endpoints.
- Verify version compliance across managed fleets and block or force-update outdated Chrome installs.
- Keep site isolation enabled and avoid disabling it for compatibility.
- Reduce renderer compromise opportunities by limiting untrusted web content and enforcing browser hardening baselines.
- Track KEV remediation deadlines and confirm closure for internet-facing and high-value users.
Detection
- Alert on Chrome versions below 86.0.4240.198 in asset inventory or endpoint telemetry.
- Monitor for browser processes spawning unexpected child processes or writing outside normal profile paths.
- Hunt for renderer crashes followed by suspicious post-exploitation activity on the same host.
- Correlate proxy or DNS logs for known exploit-delivery pages with endpoint browser version data.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-16017 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Google Chrome Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop_11.html | Release NotesVendor Advisory |
| https://crbug.com/1146709 | Permissions RequiredVendor Advisory |
| https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop_11.html | Release NotesVendor Advisory |
| https://crbug.com/1146709 | Permissions RequiredVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-16017 | US Government Resource |
Track CVE-2020-16017 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-16017), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.