CVE-2020-16040
MEDIUM 6.5EPSS 99.6%
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P - EPSS
- 99.59% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2021-01-08
- Updated
- 2024-08-04
Proof-of-concept exploits (6)
- http://packetstormsecurity.com/files/162106/Google-Chrome-86.0.4240-V8-Remote-Code-Execut…
- http://packetstormsecurity.com/files/162144/Google-Chrome-SimplfiedLowering-Integer-Overf…
- anvbis/trivialize5★ · 2023-03-15
- maldev866/ChExp_CVE_2020_160401★ · 2023-03-07
- r4j0x00/exploits2525★ · 2023-01-02
- yuvaly0/exploits30★ · 2025-07-18