CVE-2020-6495 describes an insufficient policy enforcement vulnerability in Google Chrome's developer tools, affecting versions prior to 83.0.4103.97, as well as Debian and openSUSE distributions. This medium-severity flaw (CVSS 6.5) allows an attacker to achieve a sandbox escape through a crafted Chrome Extension, provided they can convince a user to install it. While the attack requires user interaction, it could lead to high integrity impact. There is no evidence of active exploitation, no public exploit code, and minimal community discussion or media coverage, indicating a low current threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 83.0.4103.97CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
sle-15CPE matchmatch criteria | cpe:2.3:o:opensuse:backports:sle-15:sp1:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.