CVE-2020-6562 describes an insufficient policy enforcement vulnerability in Google Chrome's Blink rendering engine, affecting versions prior to 85.0.4183.83, as well as Debian, Fedora, and OpenSUSE. This medium-severity vulnerability (CVSS 6.5) allows a remote attacker to leak cross-origin data through a crafted HTML page, requiring user interaction but having a low attack complexity. While there is no evidence of active exploitation, no public exploit code, and it's not on CISA's KEV catalog, the vulnerability has garnered some community discussion and media coverage, indicating a degree of awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 85.0.4183.83CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:a:opensuse:backports_sle:15.0:sp2:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.