CVE-2020-6385: High severity Google Chrome vulnerability
An insufficient policy enforcement flaw was found in the storage component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1035399
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Other sources
Insufficient policy enforcement in storage in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass site isolation via a crafted HTML page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 90.0.4430.212-1~deb10u1Fixed in 116.0.5845.180-1~deb11u1Fixed in 120.0.6099.129-1~deb11u1Fixed in 119.0.6045.199-1~deb12u1Fixed in 120.0.6099.129-1~deb12u1Fixed in 120.0.6099.129-1 - Upgrade
Upgrade
redhat/chromium-browserto a version that resolves this vulnerability.Fixed in 80.0.3987.87 - Upgrade
Upgrade
chromium/chrometo a version that resolves this vulnerability.Fixed in 80.0.3987.87
Event History
Frequently Asked Questions
What is CVE-2020-6385?
CVE-2020-6385 is a vulnerability in Google Chrome that allowed a remote attacker to bypass site isolation via a crafted HTML page.
How severe is CVE-2020-6385?
CVE-2020-6385 has a severity rating of 8.8, which is considered high.
Which software versions are affected by CVE-2020-6385?
The affected software versions include Google Chrome prior to 80.0.3987.87, Debian Chromium, Red Hat Chromium Browser, openSUSE Backports SLE, Fedora, Debian Linux, SUSE Package Hub, SUSE Linux Enterprise, and Red Hat Enterprise Linux.
How can I fix CVE-2020-6385?
To fix CVE-2020-6385, ensure that you update your Google Chrome to version 80.0.3987.87 or later.
Where can I find more information about CVE-2020-6385?
You can find more information about CVE-2020-6385 on the Debian Security Tracker and the Google Chromium issue tracker.