Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android. | Apply updates per vendor instructions.
Google Chrome FreeType
Exploit
CVE-2020-15999
CISA KEV
Apply patch by 2021-11-17