CVE-2020-6490: Medium severity google chrome vulnerability
Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been able to write to disk to leak cross-origin data via a crafted HTML page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-6490?
CVE-2020-6490 has been classified with a high severity rating due to its potential to leak sensitive cross-origin data.
How do I fix CVE-2020-6490?
To fix CVE-2020-6490, update Google Chrome or Chromium to version 83.0.4103.61 or later.
What does CVE-2020-6490 affect?
CVE-2020-6490 affects Google Chrome versions prior to 83.0.4103.61 and specific versions of Chromium on Debian and openSUSE.
What type of vulnerability is CVE-2020-6490?
CVE-2020-6490 is an insufficient data validation vulnerability located in the loader of Google Chrome.
Can CVE-2020-6490 be exploited remotely?
Yes, CVE-2020-6490 can be exploited remotely by a malicious attacker able to write to disk, allowing them to leak cross-origin data.