CVE-2020-15999 — Google Chrome FreeType Heap Buffer Overflow Vulnerability
CVE-2020-15999: Google Chrome FreeType Heap Buffer Overflow Vulnerability
CISA Known Exploited Vulnerability (KEV)
| Vendor / project | |
| Product | Chrome FreeType |
| Date added | 2021-11-03 |
| Due date | 2021-11-17 |
| Ransomware campaign use | Unknown |
Description
Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.
Required action (CISA)
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2020-15999
References
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2020-15999
- KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog