CVE-2020-16040Active Exploitation(google / chrome)

HIGHCVSS 6.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch google chrome systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-190CWE-787

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome

Threat summary

  • Active exploitation appears in 4 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days

What's happening

  • Active exploitation reported across 4 signals
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 1 signal
  • General: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-02-01); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
chrome

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-02-01: 1Mentions · 2026-02-02: 1Mentions · 2026-02-17: 1Mentions · 2026-02-24: 1Mentions · 2026-03-14: 1Exploit Tool / Code · 2026-02-24: 1Active Exploitation · 2026-02-01: 1Active Exploitation · 2026-02-02: 1Active Exploitation · 2026-02-17: 1Active Exploitation · 2026-02-24: 1Patch / Workaround · 2026-02-24: 102-0102-0202-1702-2403-14
Signal classification2 categories
Active Exploitation
480.0%
General
120.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-011
Active Exploitation1
2026-02-021
Active Exploitation1
2026-02-171
Active Exploitation1
2026-02-241
Active Exploitation1
2026-03-141
General1
Full discourse5 posts
  • Cybersecurity News Everyday@TweetThreatNews
    General

    Trend Micro uncovers PeckBirdy, a JavaScript C2 framework linked to China-aligned APTs since 2023. Tied to modular backdoors, stolen certificates, Cobalt Strike, and CVE-2020-16040 exploits. #PeckBirdy #ChinaAPT #CodeSigning https://ift.tt/NAGhyn9

    Post summary

    Trend Micro reports the PeckBirdy JavaScript C2 framework used by China‑aligned APTs, noting associations with modular backdoors, stolen certificates, Cobalt Strike, and the CVE‑2020‑16040 exploit, but provides no details on PoC, active exploitation, or patches.

    00020228
    3.7K followersView on X
  • BreachBriefs@BreachBrief
    Active Exploitation

    Chinese APT groups (Shadow-Void-044, Shadow-Earth-045/Earth Baxia links) attacking Asian govt's, private orgs & Chinese gambling sites with high-end PeckBirdy C2 framework since 2023. Delivers modular backdoors (Holodonut, MKDoor) via fake Chrome updates + CVE-2020-16040 exploit. Blurs cybercrime (financial) & espionage lines in APAC—over 50% of global APTs! Patch & monitor. #CyberEspionage #ChinaAPT

    Post summary

    Chinese APT groups are actively exploiting CVE‑2020‑16040 via fake Chrome updates to deliver backdoors, and a patch is recommended.

    1001062
    6 followersView on X
  • TrendAI™ Research@trendai_RSRCH
    Active Exploitation

    TrendAI™ Research observed PeckBirdy, a JScript-based C&C framework, delivering fake Chrome updates, exploiting CVE-2020-16040 and launching reverse shells. Full attack chain analysis is on our blog: https://research.trendmicro.com/4qJkwVU

    Post summary

    TrendAI observed the PeckBirdy malware actively exploiting CVE-2020-16040 via fake Chrome updates and reverse shells, confirming in-the-wild attacks.

    00020395
    51.6K followersView on X
  • TrendAI™ Research@trendai_RSRCH
    Active Exploitation

    TrendAI™ Research observed PeckBirdy, a JScript-based C&C framework, delivering fake Chrome updates, exploiting CVE-2020-16040 and launching reverse shells. Full attack chain analysis is on our blog: https://research.trendmicro.com/4qJkwVU

    Post summary

    TrendAI Research reports that CVE-2020-16040 is actively exploited by the PeckBirdy team, which distributes falsified Chrome updates and achieves reverse shells.

    00011527
    51.6K followersView on X
  • TrendAI™ Research@trendai_RSRCH
    Active Exploitation

    TrendAI™ Research observed PeckBirdy, a JScript-based C&C framework, delivering fake Chrome updates, exploiting CVE-2020-16040 and launching reverse shells. Full attack chain analysis is on our blog: https://research.trendmicro.com/4qJkwVU

    Post summary

    TrendAI research reports that the JScript-based PeckBirdy framework is actively exploiting CVE-2020-16040 by delivering fake Chrome updates and launching reverse shells.

    00010385
    51.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---

Explore more