First published: Thu Nov 28 2019(Updated: )
Inappropriate implementation in interstitials in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Credit: Vladimir Metnew @vladimir_metnew chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <80.0.3987.87 | |
Google Chrome | <80.0.3987.87 | 80.0.3987.87 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-6500 has a severity rating of medium due to its potential to allow URL spoofing.
To fix CVE-2020-6500, update Google Chrome to version 80.0.3987.87 or later.
The risks associated with CVE-2020-6500 include the ability for remote attackers to spoof the URL bar, potentially leading to phishing attacks.
CVE-2020-6500 affects versions of Google Chrome prior to 80.0.3987.87.
Yes, CVE-2020-6500 can be exploited remotely through a crafted HTML page that deceives users regarding their URL.