Exploited Vulnerabilities Daily
🌐 English

Home › Google

CVE-2020-15999: Google Chrome FreeType

EPSS63.8%No. 771 of 1739 in KEV
CVE year2020~1 yrs before listing
Same vendor in KEV75
Same product1
FieldValue
VendorGoogle
ProductChrome FreeType
NameGoogle Chrome FreeType Heap Buffer Overflow Vulnerability
Added to KEV2021-11-03
US federal due date2021-11-17
Ransomware useUnknown
CWECWE-787

CISA description

Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.

NVD — CVE-2020-15999

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Google Chrome FreeType vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03.