CVE-2020-6435: Medium severity Google Chrome vulnerability
Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 90.0.4430.212-1~deb10u1Fixed in 116.0.5845.180-1~deb11u1Fixed in 120.0.6099.129-1~deb11u1Fixed in 119.0.6045.199-1~deb12u1Fixed in 120.0.6099.129-1~deb12u1Fixed in 120.0.6099.129-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 81.0.4044.92
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2020-6435.
What is the affected software for this vulnerability?
The affected software for this vulnerability includes Google Chrome prior to version 81.0.4044.92, Debian Linux 9.0 and 10.0, Fedora 30, 31, and 32, openSUSE Leap 15.1, and chromium on Debian.
What is the severity rating of CVE-2020-6435?
The severity rating of CVE-2020-6435 is medium (4.3).
How can an attacker exploit this vulnerability?
An attacker who has compromised the renderer process can exploit this vulnerability by bypassing navigation restrictions via a crafted HTML page.
How can I fix this vulnerability?
To fix this vulnerability, update Google Chrome to version 81.0.4044.92, Debian Linux to the recommended remedy versions, Fedora to the recommended remedy versions, openSUSE Leap to the recommended remedy version, or update chromium on Debian to the recommended remedy versions.