Published: 03/06/2020 Updated: 14/10/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Insufficient policy enforcement in Omnibox in Google Chrome on iOS before 83.0.4103.88 allowed a remote malicious user to perform domain spoofing via a crafted URI.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

debian debian linux 9.0

debian debian linux 10.0

Vendor Advisories

The stable channel has been updated to 830410397 for Windows, Mac, and Linux, which will roll out over the coming days/weeks Security Fixes and Rewards Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix We will also retain restrictions if the bug exists in a third party lib ...
Several vulnerabilities have been discovered in the chromium web browser CVE-2020-6423 A use-after-free issue was found in the audio implementation CVE-2020-6430 Avihay Cohen discovered a type confusion issue in the v8 javascript library CVE-2020-6431 Luan Herrera discovered a policy enforcement error CVE-2020-6432 Luan Her ...

Github Repositories

CVE-2020-6497 Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 830410388 allowed a remote attacker to perform domain spoofing via a crafted URI authentication complexity vector NONE MEDIUM NETWORK confidentiality integrity availability NONE PARTIAL NONE CVSS Score: 43 References chromereleasesgoogleblogcom/2020/06/