Heap buffer overflow in CefSharp
Description
Reviewed
Oct 27, 2020
Published to the GitHub Advisory Database
Oct 27, 2020
Published by the National Vulnerability Database
Nov 3, 2020
Last updated
Feb 3, 2025
Impact
A memory corruption bug(Heap overflow) in the FreeType font rendering library.
As per https://www.secpod.com/blog/chrome-zero-day-under-active-exploitation-patch-now/
Google is aware of reports that an exploit for CVE-2020-15999 exists in the wild.
Patches
Upgrade to 85.3.130 or higher
References
To review the
CEF/Chromium
patch see https://bitbucket.org/chromiumembedded/cef/commits/cd6cbe008b127990036945fb75e7c2c1594ab10dReferences