Umbra Wiki cve cve/CVE-2020-15999
Back to wiki

CVE-2020-15999 — Google Chrome FreeType Heap Buffer Overflow Vulnerability

provenance: imported · CVE: CVE-2020-15999

CVE-2020-15999: Google Chrome FreeType Heap Buffer Overflow Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Google
Product Chrome FreeType
Date added 2021-11-03
Due date 2021-11-17
Ransomware campaign use Unknown

Description

Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2020-15999

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2020-15999
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog