LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-6572: Google Chrome Media Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 10, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 10, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-6572 to its Known Exploited Vulnerabilities catalog on Jan 10, 2022, with a federal patch deadline of Jul 10, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page.

CVE-2020-6572 is a use-after-free vulnerability in Google Chrome Media. A remote attacker can exploit it by luring a user to a crafted HTML page, which can lead to code execution in the browser context. For IT and security teams this matters because Chrome is widely deployed on endpoints; successful exploitation can give an attacker a foothold on the user’s system without needing prior access.

Public detail is limited to the CISA description and the CWE classification. Confirm exact affected builds, fixed releases, and any additional constraints against the vendor advisory before acting.

How it works

The weakness is CWE-416 (use-after-free). In this class of flaw, the application frees a block of memory but later continues to use a pointer to that memory. An attacker who can influence allocation and free timing—here via a crafted HTML page that exercises Chrome’s media handling—may be able to reuse the freed region with attacker-controlled data. That can corrupt program state and, in a browser renderer or related media component, escalate to arbitrary code execution.

No exploit mechanics, proof-of-concept details, or specific media APIs are provided in the available facts. Treat the attack surface as any untrusted web content that reaches Chrome’s media processing path, and verify the precise trigger conditions in the vendor advisory.

Am I affected? How to find it in your systems

Google Chrome is typically installed on user workstations, VDI images, and some kiosk or shared systems. Inventory every managed and unmanaged endpoint that runs Chrome, including any enterprise-managed channels or secondary browsers that embed Chromium media components if your environment uses them.

How to remediate

Patch first. Apply the Chrome updates specified by the vendor, following CISA’s required action: apply updates per vendor instructions. Use your standard enterprise deployment path (auto-update, managed update policies, or packaged rollout) and verify that endpoints actually reach the fixed build.

If you can't patch immediately

Reduce risk with compensating controls until the vendor update is deployed everywhere.

These steps do not eliminate the vulnerability; they only lower likelihood and impact until patches are applied.

If your data may have been exposed

Actively exploited browser code-execution flaws can lead to endpoint compromise and subsequent data theft. Known ransomware use is not documented for this CVE. If you suspect exploitation, isolate affected hosts, preserve volatile evidence, rotate credentials accessible from those systems, and follow your incident-response process. You can run a free exposure scan of your email addresses against known breach data to check whether credentials or personal data have appeared in prior breaches while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGoogle · Chrome Media
WeaknessCWE-416
Added to CISA KEVJan 10, 2022
Federal patch deadlineJul 10, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities