← Back to browse · API

CVE-2020-15999

Severity
CRITICAL
CVSS
9.6
EPSS
0.5063
Risk score
81.12
CISA KEV
Yes
PoC
Yes
Published
2021-11-03
Modified
2021-11-03
First seen
2026-08-07
Aliases
EUVD-2020-1435, GHSA-PV36-H7JH-QM62
Products
Google:Chrome FreeType, Google:Chrome unspecified <86.0.4240.111, linux, suse
Sources
euvd EUVD-2020-1435
cisa.gov CVE-2020-15999
packetstorm ca76e90ea4bb0b06eb5fa94d|CVE-2020-15999
packetstorm 95f83ec6f7612bf3797dd02e|CVE-2020-15999

Description

Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.

References