CVE-2020-6575: Race in Mojo
Race in Mojo in Google Chrome prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Credit
Affected Software
Remediation
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-6575?
CVE-2020-6575 is a vulnerability in Mojo in Google Chrome prior to version 85.0.4183.102.
How can an attacker exploit CVE-2020-6575?
An attacker who has compromised the renderer process can potentially perform a sandbox escape via a crafted HTML page.
Which software versions are affected by CVE-2020-6575?
Google Chrome versions prior to 85.0.4183.102, openSUSE Backports SLE 15.0-sp1 and 15.0-sp2, Debian Debian Linux 10.0, Fedoraproject Fedora 31 and 33, and openSUSE Leap 15.1 and 15.2 are affected.
What is the severity of CVE-2020-6575?
CVE-2020-6575 has a severity score of 8.3 (High).
How do I fix CVE-2020-6575?
To fix CVE-2020-6575, update to Google Chrome version 85.0.4183.102 or later, or follow the provided update instructions for other affected software.