CVE-2020-36765: Insufficient policy enforcement in Navigation
Published Apr 12, 2018
·Updated
Insufficient policy enforcement in Navigation in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Credit
Jun Kokatsu@@shhnjk
Affected Software
2 affected componentsFixes available
Google Chrome<85.0.4183.83
85.0.4183.83
Google Chrome<85.0.4183.83
Event History
Apr 12, 2018
CVE Published
12:00 AM
Jul 16, 2024
CVE Published
via MITRE·10:30 PM
Data Sourced
via MITRE·10:30 PM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
Description
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2020-36765?
The severity of CVE-2020-36765 is classified as Medium.
2
How do I fix CVE-2020-36765?
To fix CVE-2020-36765, you should update Google Chrome to version 85.0.4183.83 or later.
3
What type of vulnerability is CVE-2020-36765?
CVE-2020-36765 is an insufficient policy enforcement vulnerability in Navigation in Google Chrome.
4
Can CVE-2020-36765 lead to data leakage?
Yes, CVE-2020-36765 allows a remote attacker to leak cross-origin data via a crafted HTML page.
5
Which versions of Google Chrome are affected by CVE-2020-36765?
CVE-2020-36765 affects Google Chrome versions prior to 85.0.4183.83.