CVE-2020-6446: Medium severity Google Chrome vulnerability
Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 90.0.4430.212-1~deb10u1Fixed in 116.0.5845.180-1~deb11u1Fixed in 120.0.6099.129-1~deb11u1Fixed in 119.0.6045.199-1~deb12u1Fixed in 120.0.6099.129-1~deb12u1Fixed in 120.0.6099.129-1
Event History
Frequently Asked Questions
What is CVE-2020-6446?
CVE-2020-6446 is a vulnerability in Google Chrome that allows a remote attacker to bypass content security policy via a crafted HTML page.
How does CVE-2020-6446 affect Google Chrome?
CVE-2020-6446 affects Google Chrome versions prior to 81.0.4044.92.
What is the severity of CVE-2020-6446?
CVE-2020-6446 has a severity score of 6.5 (medium).
Which software versions are affected by CVE-2020-6446?
CVE-2020-6446 affects Google Chrome prior to 81.0.4044.92, Debian Linux 9.0, Debian Linux 10.0, Fedora 30, Fedora 31, Fedora 32, openSUSE Leap 15.1, and openSUSE Backports sle-15-sp1.
How can I fix CVE-2020-6446?
To fix CVE-2020-6446, update to Google Chrome version 81.0.4044.92 or later.