CVE-2020-6501: Insufficient validation of untrusted input in Omnibox.
Published Feb 7, 2019
·Updated
Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Credit
Khalil Zhani
Affected Software
2 affected componentsFixes available
Google Chrome<80.0.3987.87
80.0.3987.87
Google Chrome<80.0.3987.87
Event History
Feb 7, 2019
CVE Published
12:00 AM
Jun 3, 2020
CVE Published
via MITRE·10:50 PM
Data Sourced
via MITRE·10:50 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-6381
- CVE-2020-6382
- CVE-2019-18197
- CVE-2019-19926
- CVE-2020-6385
- CVE-2019-19880
- CVE-2019-19925
- CVE-2020-6387
- CVE-2020-6388
- CVE-2020-6389
- CVE-2020-6390
- CVE-2020-6391
- CVE-2020-6392
- CVE-2020-6393
- CVE-2020-6499
- CVE-2020-6394
- CVE-2020-6395
- CVE-2020-6396
- CVE-2020-6397
- CVE-2020-6398
- CVE-2020-6399
- CVE-2020-6500
- CVE-2020-6400
- CVE-2020-6401
- CVE-2020-6402
- CVE-2020-6403
- CVE-2020-6404
- CVE-2020-6405
- CVE-2020-6406
- CVE-2019-19923
- CVE-2020-6408
- CVE-2020-6409
- CVE-2020-6410
- CVE-2020-6411
- CVE-2020-6502
- CVE-2020-6412
- CVE-2020-6413
- CVE-2020-6414
- CVE-2020-6415
- CVE-2020-6416
- CVE-2020-6417
Frequently Asked Questions
1
What is the severity of CVE-2020-6501?
CVE-2020-6501 is classified as a high-severity vulnerability.
2
How do I fix CVE-2020-6501?
To fix CVE-2020-6501, update Google Chrome to version 80.0.3987.87 or later.
3
What impact does CVE-2020-6501 have on users?
CVE-2020-6501 allows remote attackers to bypass content security policy, potentially leading to unauthorized actions or data exposure.
4
Which versions of Google Chrome are affected by CVE-2020-6501?
CVE-2020-6501 affects Google Chrome versions prior to 80.0.3987.87.
5
Who is the vendor associated with CVE-2020-6501?
The vendor associated with CVE-2020-6501 is Google.