CVE-2020-6549 is a use-after-free vulnerability in Google Chrome prior to version 84.0.4147.125, affecting various Google Chrome and associated Debian/Fedora distributions. This flaw allows a remote attacker to potentially exploit heap corruption by enticing a user to visit a specially crafted HTML page. Rated with a CVSS score of 8.8 (High), this vulnerability requires user interaction (UI:R) but has low attack complexity (AC:L) and no authentication required (PR:N), leading to high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H). The EPSS score indicates a higher than average likelihood of exploitation compared to other CVEs. While there is no evidence of active exploitation (KEV: No) or publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion and media coverage, including reports of a $10,000 reward for its discovery.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 84.0.4147.125CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.