CVE-2020-6415 describes a heap corruption vulnerability in Google Chrome versions prior to 80.0.3987.87, stemming from an inappropriate JavaScript implementation. This flaw could be triggered by a remote attacker through a specially crafted HTML page, impacting various distributions including Debian, Fedora, openSUSE, Red Hat, and SUSE. The vulnerability carries a high severity CVSS score of 8.8, indicating a critical risk. It can be exploited remotely with low attack complexity, requiring user interaction (UI:R) to visit a malicious page. Successful exploitation could lead to high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H). While there is no evidence of active exploitation (KEV: No) and no public exploit code available in Metasploit, Nuclei, or ExploitDB, the vulnerability garnered some community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 80.0.3987.87CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.