CVE-2020-6408: Medium severity Google Chrome vulnerability
An insufficient policy enforcement flaw was found in the CORS component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1026546
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Other sources
Insufficient policy enforcement in CORS in Google Chrome prior to 80.0.3987.87 allowed a local attacker to obtain potentially sensitive information via a crafted HTML page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 90.0.4430.212-1~deb10u1Fixed in 116.0.5845.180-1~deb11u1Fixed in 120.0.6099.129-1~deb11u1Fixed in 119.0.6045.199-1~deb12u1Fixed in 120.0.6099.129-1~deb12u1Fixed in 120.0.6099.129-1 - Upgrade
Upgrade
redhat/chromium-browserto a version that resolves this vulnerability.Fixed in 80.0.3987.87 - Upgrade
Upgrade
chromium/google chrometo a version that resolves this vulnerability.Fixed in 80.0.3987.87 - Compensating control
Mitigate exposure by preventing untrusted/crafted HTML pages from being loaded in the browser (e.g., restrict browsing to trusted sources) until all Chromium/Chrome installations are updated to address the CORS policy enforcement flaw.
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-6408.
What is the title of this vulnerability?
The title of this vulnerability is 'Insufficient policy enforcement in CORS in Google Chrome prior to 80.0.3987.87 allowed a local attacker to obtain potentially sensitive information via a crafted HTML page.'
What is the severity of CVE-2020-6408?
The severity of CVE-2020-6408 is medium with a score of 6.5.
What software versions are affected by this vulnerability?
Google Chrome prior to 80.0.3987.87, chromium-browser (remedy version 80.0.3987.87), chromium, and some other Linux distributions are affected by this vulnerability.
How can I fix CVE-2020-6408?
To fix CVE-2020-6408, update your Google Chrome browser to version 80.0.3987.87 or higher.