Skip to content

Use after free in site isolation (CVE-2020-16017)

High
amaitland published GHSA-gvqv-779r-4jgp Nov 27, 2020

Package

nuget CefSharp.Common, CefSharp.Wpf, CefSharp.WinForms, CefSharp.Wpf, CefSharp.Wpf.HwndHost (Nuget)

Affected versions

< 86.0.241

Patched versions

86.0.241

Description

CVE-2020-16017: Use after free in site isolation

Google is aware of reports that exploits for CVE-2020-16013 and CVE-2020-16017 exist in the wild.

There is currently little to no public information on the issue other than it has been flagged as High severity.

Severity

High

CVE ID

CVE-2020-16017

Weaknesses

No CWEs