CVE-2020-6403 describes an incorrect implementation in the Omnibox (URL bar) of Google Chrome on iOS, affecting versions prior to 80.0.3987.87. This vulnerability allowed a remote attacker to spoof the Omnibox's contents through a specially crafted HTML page, impacting various products including Google, Apple, Debian, and Red Hat. Rated as Medium severity (CVSS 4.3), it requires user interaction (UI:R) via a network-based attack (AV:N) with low attack complexity (AC:L), primarily leading to a low impact on integrity (I:L) without affecting confidentiality or availability. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and it has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 80.0.3987.87CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.