CVE-2020-6402: Input Validation
An insufficient policy enforcement flaw was found in the downloads component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1029375
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Other sources
Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 90.0.4430.212-1~deb10u1Fixed in 116.0.5845.180-1~deb11u1Fixed in 120.0.6099.129-1~deb11u1Fixed in 119.0.6045.199-1~deb12u1Fixed in 120.0.6099.129-1~deb12u1Fixed in 120.0.6099.129-1 - Upgrade
Upgrade
redhat/chromium-browserto a version that resolves this vulnerability.Fixed in 80.0.3987.87 - Upgrade
Upgrade
chromium/google chrome downloads component (OS X)to a version that resolves this vulnerability.Fixed in 80.0.3987.87 - Compensating control
Ensure Chrome Extension installation is restricted/controlled so users cannot install malicious extensions (e.g., limit extension installation to trusted/managed sources) to prevent exploitation of the downloads policy enforcement flaw.
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2020-6402.
What is the severity level of CVE-2020-6402?
The severity level of CVE-2020-6402 is high, with a severity value of 8.8.
How does this vulnerability affect Google Chrome on OS X?
This vulnerability affects Google Chrome on OS X prior to version 80.0.3987.87.
What is the impact of CVE-2020-6402?
CVE-2020-6402 allows an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.
How can the vulnerability CVE-2020-6402 be fixed?
To fix the vulnerability CVE-2020-6402, update Google Chrome on OS X to version 80.0.3987.87 or later.