CVE-2020-6463 is a use-after-free vulnerability in ANGLE within Google Chrome prior to version 81.0.4044.122, allowing a remote attacker to potentially exploit heap corruption through a crafted HTML page. This high-severity vulnerability (CVSS 8.8) can be exploited with low attack complexity via a network and user interaction, leading to high impacts on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, its FAUCET Risk Score of 75/100 and significant media coverage (2 articles) indicate notable community attention, though no public exploit code or active exploitation is currently reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 81.0.4044.122CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.