CVE-2020-6548 describes a high-severity heap buffer overflow in Skia, a graphics engine used by Google Chrome prior to version 84.0.4147.125, affecting various Chrome and Debian/Fedora distributions. A remote attacker could exploit this vulnerability via a crafted HTML page, potentially leading to heap corruption and allowing for high impact to confidentiality, integrity, and availability if the renderer process is compromised. While there is no evidence of active exploitation (KEV list) or public exploit code (Metasploit, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness despite its inactive status on the CISA Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 84.0.4147.125CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.