VYPR
High severityCISA KEVNVD Advisory· Published Jan 8, 2021· Updated Oct 21, 2025

CVE-2020-16017

CVE-2020-16017

Description

Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
CefSharp.CommonNuGet
< 86.0.24186.0.241
CefSharp.WpfNuGet
< 86.0.24186.0.241
CefSharp.WinFormsNuGet
< 86.0.24186.0.241
CefSharp.Wpf.HwndHostNuGet
< 86.0.24186.0.241

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.