← Back to browse · API

CVE-2020-16017

Severity
CRITICAL
CVSS
9.6
EPSS
0.02747
Risk score
64.36
CISA KEV
Yes
PoC
No
Published
2021-01-08
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2020-1456, GHSA-GVQV-779R-4JGP
Products
Google:Chrome, Google:Chrome unspecified <86.0.4240.198
Sources
cisa.gov CVE-2020-16017
euvd EUVD-2020-1456

Description

Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

References