CVE-2020-6493: Use After Free
Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-6493?
CVE-2020-6493 is a vulnerability in WebAuthentication in Google Chrome prior to version 83.0.4103.97.
What is the severity level of CVE-2020-6493?
The severity level of CVE-2020-6493 is critical, with a severity value of 9.6.
How does CVE-2020-6493 work?
CVE-2020-6493 allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Which software versions are affected by CVE-2020-6493?
Google Chrome versions prior to 83.0.4103.97, Debian Linux 9.0 and 10.0, openSUSE Leap 15.1, and Debian Chromium packages are affected by CVE-2020-6493.
How can I fix CVE-2020-6493?
To fix CVE-2020-6493, update Google Chrome to version 83.0.4103.97 or later, Debian Linux to the recommended versions, openSUSE Leap to the recommended version, and Debian Chromium packages to the recommended versions.