605
VMScore

CVE-2020-6461

Published: 21/05/2020 Updated: 05/10/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 9.6 | Impact Score: 6 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Use after free in storage in Google Chrome before 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

debian debian linux 9.0

debian debian linux 10.0

Vendor Advisories

Synopsis Important: chromium-browser security update Type/Severity Security Advisory: Important Topic An update for chromium-browser is now available for Red Hat Enterprise Linux 6 SupplementaryRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability S ...
Several vulnerabilities have been discovered in the chromium web browser CVE-2020-6423 A use-after-free issue was found in the audio implementation CVE-2020-6430 Avihay Cohen discovered a type confusion issue in the v8 javascript library CVE-2020-6431 Luan Herrera discovered a policy enforcement error CVE-2020-6432 Luan Her ...
A use-after-free vulnerability has been found in the storage component of the chromium browser before 8104044129 ...
The stable channel has been updated to 8104044129 for Windows, Mac, and Linux, which will roll out over the coming days/weeks A list of all changes is available in the log Interested in switching release channels? Find out how If you find a new issue, please let us know by filing a bug The community help forum is also a great pl ...

Recent Articles

Xiaomi emits phone browser updates after almighty row over web activity harvested even in incognito mode
The Register • Shaun Nichols in San Francisco • 04 May 2020

Plus: Other infosec news from around the internet

Roundup Congratulations, everyone. We made it through April. Here's a handy mop-up of bits and bytes of security news beyond what we covered in The Reg. A Forbes report last week outlined how some Xiaomi Android phones track their owners' web browsing and online activities. It was claimed the handsets' bundled Xiaomi browser collects things like browsing history, search queries, and news feed activity, and sends the data off to servers in China, even in private incognito mode. Xiaomi, in respons...