CVE-2020-6541 is a use-after-free vulnerability in WebUSB within Google Chrome versions prior to 84.0.4147.105, affecting various distributions including Debian and Fedora. This high-severity vulnerability (CVSS 8.8) allows a remote attacker to achieve heap corruption and potentially execute arbitrary code by enticing a user to visit a crafted HTML page. While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) has been identified, it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 84.0.4147.105CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.