CVE-2020-6443: High severity Google Chrome vulnerability
Insufficient data validation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced the user to use devtools to execute arbitrary code via a crafted HTML page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 90.0.4430.212-1~deb10u1Fixed in 116.0.5845.180-1~deb11u1Fixed in 120.0.6099.129-1~deb11u1Fixed in 119.0.6045.199-1~deb12u1Fixed in 120.0.6099.129-1~deb12u1Fixed in 120.0.6099.129-1
Event History
Frequently Asked Questions
What is CVE-2020-6443?
CVE-2020-6443 is a vulnerability in developer tools in Google Chrome that allows remote attackers to execute arbitrary code.
What is the severity of CVE-2020-6443?
CVE-2020-6443 has a severity value of 8.8, which is considered high.
Which software versions are affected by CVE-2020-6443?
CVE-2020-6443 affects Google Chrome versions prior to 81.0.4044.92, Debian Linux version 9.0, Debian Linux version 10.0, Fedora versions 30, 31, and 32, openSUSE Leap version 15.1, and openSUSE Backports version sle-15-sp1.
How can the CVE-2020-6443 vulnerability be fixed?
To fix CVE-2020-6443, update Google Chrome to version 81.0.4044.92 or newer. For Debian Linux, update the Chromium package to version 90.0.4430.212-1~deb10u1 or newer.
Where can I find more information about CVE-2020-6443?
More information about CVE-2020-6443 can be found at the Debian Security Tracker and the openSUSE Security Announce.