CVE-2020-15999: Google Chrome FreeType Heap Buffer Overflow Vulnerability

Critical severity, CVSS 9.6. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 63.9% chance of exploitation in the next 30 days.

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Fedoraproject Fedora: version 31 only
  • FreeType FreeType: from 2.6.0, before 2.10.4 (fixed in 2.10.4)
  • Google Chrome: before 86.0.4240.111 (fixed in 86.0.4240.111)
  • Netapp Ontap Select Deploy Administration Utility: affected versions not specified
  • Opensuse Backports Sle: version 15.0 only

Published 2020-11-03. Last modified 2026-06-17.