CVE-2020-15999: Google Chrome FreeType
EPSS63.8%No. 771 of 1739 in KEV
CVE year2020~1 yrs before listing
Same vendor in KEV75
Same product1
| Field | Value |
|---|---|
| Vendor | |
| Product | Chrome FreeType |
| Name | Google Chrome FreeType Heap Buffer Overflow Vulnerability |
| Added to KEV | 2021-11-03 |
| US federal due date | 2021-11-17 |
| Ransomware use | Unknown |
| CWE | CWE-787 |
CISA description
Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Google Chrome FreeType vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03.