CVE-2020-6504: Insufficient policy enforcement in notifications
Published Aug 17, 2018
·Updated
Insufficient policy enforcement in notifications in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass notification restrictions via a crafted HTML page.
Credit
Alessio Di Maria
Affected Software
2 affected componentsFixes available
Google Chrome<74.0.3729.108
74.0.3729.108
Google Chrome<74.0.3729.108
Event History
Aug 17, 2018
CVE Published
12:00 AM
Jun 3, 2020
CVE Published
via MITRE·10:50 PM
Data Sourced
via MITRE·10:50 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2020-6504?
CVE-2020-6504 is classified as a medium severity vulnerability.
2
How do I fix CVE-2020-6504?
To fix CVE-2020-6504, upgrade Google Chrome to version 74.0.3729.108 or later.
3
What type of attack does CVE-2020-6504 allow?
CVE-2020-6504 allows a remote attacker to bypass notification restrictions using a crafted HTML page.
4
Which versions of Google Chrome are affected by CVE-2020-6504?
CVE-2020-6504 affects all versions of Google Chrome prior to 74.0.3729.108.
5
Is CVE-2020-6504 a local or remote vulnerability?
CVE-2020-6504 is a remote vulnerability that can be exploited through a crafted HTML page.