CVE-2020-6500: Insufficient policy enforcement in downloads.
Published Nov 28, 2019
·Updated
Inappropriate implementation in interstitials in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Credit
Vladimir Metnew@@vladimir_metnew
Affected Software
2 affected componentsFixes available
Google Chrome<80.0.3987.87
80.0.3987.87
Google Chrome<80.0.3987.87
Event History
Nov 28, 2019
CVE Published
12:00 AM
Jun 3, 2020
CVE Published
via MITRE·10:50 PM
Data Sourced
via MITRE·10:50 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-6381
- CVE-2020-6382
- CVE-2019-18197
- CVE-2019-19926
- CVE-2020-6385
- CVE-2019-19880
- CVE-2019-19925
- CVE-2020-6387
- CVE-2020-6388
- CVE-2020-6389
- CVE-2020-6390
- CVE-2020-6391
- CVE-2020-6392
- CVE-2020-6393
- CVE-2020-6499
- CVE-2020-6394
- CVE-2020-6395
- CVE-2020-6396
- CVE-2020-6397
- CVE-2020-6398
- CVE-2020-6399
- CVE-2020-6400
- CVE-2020-6401
- CVE-2020-6402
- CVE-2020-6501
- CVE-2020-6403
- CVE-2020-6404
- CVE-2020-6405
- CVE-2020-6406
- CVE-2019-19923
- CVE-2020-6408
- CVE-2020-6409
- CVE-2020-6410
- CVE-2020-6411
- CVE-2020-6502
- CVE-2020-6412
- CVE-2020-6413
- CVE-2020-6414
- CVE-2020-6415
- CVE-2020-6416
- CVE-2020-6417
Frequently Asked Questions
1
What is the severity of CVE-2020-6500?
CVE-2020-6500 has a severity rating of medium due to its potential to allow URL spoofing.
2
How do I fix CVE-2020-6500?
To fix CVE-2020-6500, update Google Chrome to version 80.0.3987.87 or later.
3
What are the risks associated with CVE-2020-6500?
The risks associated with CVE-2020-6500 include the ability for remote attackers to spoof the URL bar, potentially leading to phishing attacks.
4
Which versions of Chrome are affected by CVE-2020-6500?
CVE-2020-6500 affects versions of Google Chrome prior to 80.0.3987.87.
5
Can CVE-2020-6500 be exploited remotely?
Yes, CVE-2020-6500 can be exploited remotely through a crafted HTML page that deceives users regarding their URL.