CVE-2020-6516 describes a policy bypass vulnerability in the Cross-Origin Resource Sharing (CORS) mechanism of Google Chrome versions prior to 84.0.4147.89, also affecting Debian, Fedora, and OpenSUSE. A remote attacker could exploit this flaw by crafting a malicious HTML page to leak cross-origin data. The vulnerability has a CVSS score of 4.3 (MEDIUM), indicating a network-based attack with low complexity, requiring user interaction, and resulting in low confidentiality impact without affecting integrity or availability. Its EPSS score of 0.03167 suggests a relatively low probability of exploitation. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Despite this, the vulnerability has garnered some community attention and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 84.0.4147.89CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:a:opensuse:backports_sle:15.0:sp2:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.