First published: Thu May 21 2020(Updated: )
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Credit: chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/chromium | 90.0.4430.212-1~deb10u1 116.0.5845.180-1~deb11u1 120.0.6099.129-1~deb11u1 119.0.6045.199-1~deb12u1 120.0.6099.129-1~deb12u1 120.0.6099.129-1 | |
Google Chrome | <83.0.4103.61 | |
openSUSE Backports | =15.0-sp1 | |
Debian Linux | =9.0 | |
Debian Linux | =10.0 | |
Red Hat Fedora | =31 | |
Red Hat Fedora | =32 | |
SUSE Linux | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6487 is classified as a medium severity vulnerability due to its ability to allow remote attackers to bypass navigation restrictions.
Users of Google Chrome versions prior to 83.0.4103.61 and specific versions of Chromium and openSUSE Backports are affected by CVE-2020-6487.
To fix CVE-2020-6487, upgrade to Google Chrome version 83.0.4103.61 or later, or update your affected Chromium version.
CVE-2020-6487 is an insufficient policy enforcement vulnerability within downloads in Google Chrome.
Yes, CVE-2020-6487 can be exploited by remote attackers via a specially crafted HTML page.