CVE-2020-16027: Insufficient policy enforcement in developer tools
Insufficient policy enforcement in developer tools in Google Chrome prior to 87.0.4280.66 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from the user's disk via a crafted Chrome Extension.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-16018
- CVE-2020-16019
- CVE-2020-16020
- CVE-2020-16021
- CVE-2020-16022
- CVE-2020-16015
- CVE-2020-16014
- CVE-2020-16023
- CVE-2020-16024
- CVE-2020-16025
- CVE-2020-16045
- CVE-2020-16026
- CVE-2020-16028
- CVE-2020-16029
- CVE-2020-16030
- CVE-2019-8075
- CVE-2020-16031
- CVE-2020-16032
- CVE-2020-16033
- CVE-2020-16034
- CVE-2020-16035
- CVE-2020-16012
- CVE-2020-16036
Frequently Asked Questions
What is the severity of CVE-2020-16027?
CVE-2020-16027 has a medium severity rating, allowing attackers to access potentially sensitive user information.
How do I fix CVE-2020-16027?
To fix CVE-2020-16027, update Google Chrome to version 87.0.4280.66 or later.
Which versions of Google Chrome are affected by CVE-2020-16027?
Google Chrome versions prior to 87.0.4280.66 are affected by CVE-2020-16027.
Can malicious extensions exploit CVE-2020-16027?
Yes, malicious extensions can use CVE-2020-16027 to extract sensitive information from a user's disk.
Is there a known exploit for CVE-2020-16027?
Yes, there are indications that CVE-2020-16027 can be exploited if a user installs a malicious Chrome extension.