CVE-2020-6540 describes a high-severity buffer overflow vulnerability in Skia, a graphics engine used by Google Chrome prior to version 84.0.4147.105, affecting various Chrome distributions on Debian and Fedora. A remote attacker could exploit this flaw by enticing a user to visit a crafted HTML page, leading to heap corruption. This vulnerability carries a CVSS score of 8.8 (HIGH), indicating a network-based attack with low complexity, requiring user interaction, and potentially resulting in high impact to confidentiality, integrity, and availability. While there is no evidence of active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 84.0.4147.105CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.