PT-2020-5708 · Google+3 · Google Chrome+3
Philipp Hancke
·
Published
2020-10-06
·
Updated
2024-06-15
·
CVE-2020-15987
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Google Chrome versions prior to 86.0.4240.75
Description:
The issue is related to a use after free in WebRTC, which could allow a remote attacker to exploit heap corruption via a crafted WebRTC stream. This may lead to unauthorized access to confidential data, disruption of data integrity, and potentially cause a denial of service.
Recommendations:
For versions prior to 86.0.4240.75, update to version 86.0.4240.75 or later to resolve the issue. As a temporary workaround, consider disabling WebRTC functionality until a patch is applied. Restrict access to WebRTC streams to minimize the risk of exploitation. Avoid using crafted WebRTC streams in affected versions until the issue is resolved.
Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Google Chrome
Red Hat
Suse