CVE-2020-6497 describes an insufficient policy enforcement vulnerability in Google Chrome's Omnibox on iOS, affecting versions prior to 83.0.4103.88. This flaw allows a remote attacker to perform domain spoofing through a crafted URI, impacting various Apple, Debian, and Google Chrome products. With a CVSS score of 6.5 (MEDIUM), this vulnerability requires user interaction (UI:R) and has a low attack complexity (AC:L), making it moderately easy to exploit. The primary impact is a high integrity loss (I:H) due to successful domain spoofing, potentially leading to phishing attacks. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While there's limited community discussion and media coverage, the vulnerability is not listed on CISA's KEV catalog or Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 83.0.4103.88CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.