CVE-2020-6449 describes a use-after-free vulnerability in Google Chrome's audio component prior to version 80.0.3987.149, allowing a remote attacker to potentially exploit heap corruption via a crafted HTML page. This high-severity vulnerability (CVSS 8.8) can lead to high impact on confidentiality, integrity, and availability, requiring user interaction through a malicious webpage. While no public exploit code or active exploitation has been confirmed (not in KEV), the vulnerability has garnered significant community discussion and media coverage, indicating notable attention from the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 80.0.3987.149CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.