LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-16010: Google Chrome for Android UI Heap Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-16010 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Google Chrome for Android UI contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a…

CVE-2020-16010 is a heap buffer overflow in the Google Chrome for Android UI component. A remote attacker who has already compromised the renderer process can use a crafted HTML page to attempt a sandbox escape. For organizations that manage Android devices or allow Chrome on Android for work use, this matters because a successful escape can expand attacker control beyond the browser sandbox and increase risk to the device and any corporate data it holds. Confirm all version and fix details against the vendor advisory.

How it works

This issue is classed as CWE-787 (out-of-bounds write). In a heap buffer overflow, code writes past the bounds of a heap-allocated buffer. In the Chrome for Android UI path described by CISA, the attacker does not start from a cold browser; they need a prior foothold in the renderer process. From there, a malicious HTML page can trigger the overflow in the UI component and potentially break out of the sandbox that is meant to contain renderer compromise.

Sandbox escape is significant because the renderer is intentionally restricted. Leaving that isolation layer can give the attacker a path toward broader process or device influence. Exact trigger conditions, memory layout, and exploit reliability are not provided in the public summary; treat any deeper technical claims as unconfirmed unless they appear in the vendor advisory or your own validated analysis.

Am I affected? How to find it in your systems

The affected software is Google Chrome for Android UI. It typically runs on Android phones and tablets where users browse with Chrome, including personally owned and corporate-managed devices that access internal web apps, SSO portals, or email.

How to remediate

Patch first. CISA’s required action is to apply updates per vendor instructions. Deploy the Chrome for Android update that addresses CVE-2020-16010 as soon as your advisory review confirms the fixed build, and verify installation through MDM or device compliance checks.

If you can't patch immediately

Reduce exposure until the vendor update is applied everywhere.

If your data may have been exposed

Actively exploited browser sandbox escapes can lead to device compromise and follow-on data theft, even when ransomware use is not documented for this CVE. If you suspect exploitation, isolate the device, preserve logs, rotate credentials and tokens used in the browser, and follow your incident response process. You can run a free exposure scan of your email to check known breach data and determine whether addresses tied to your organization already appear in public breach sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGoogle · Chrome for Android UI
WeaknessCWE-787
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities