CVE-2020-6487: Medium severity google chrome vulnerability
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-6487?
CVE-2020-6487 is classified as a medium severity vulnerability due to its ability to allow remote attackers to bypass navigation restrictions.
Who is affected by CVE-2020-6487?
Users of Google Chrome versions prior to 83.0.4103.61 and specific versions of Chromium and openSUSE Backports are affected by CVE-2020-6487.
How do I fix CVE-2020-6487?
To fix CVE-2020-6487, upgrade to Google Chrome version 83.0.4103.61 or later, or update your affected Chromium version.
What type of vulnerability is CVE-2020-6487?
CVE-2020-6487 is an insufficient policy enforcement vulnerability within downloads in Google Chrome.
Can CVE-2020-6487 be exploited remotely?
Yes, CVE-2020-6487 can be exploited by remote attackers via a specially crafted HTML page.