CVE-2020-15961Google Chrome vulnerability

10 documents8 sources
Severity
9.6CRITICALNVD
EPSS
1.4%
top 19.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 21
Latest updateMay 24

Description

Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HExploitability: 2.8 | Impact: 6.0

Affected Packages5 packages

CVEListV5google/chromeunspecified85.0.4183.121
NVDgoogle/chrome< 85.0.4183.121
Debianchromium/chromium< 87.0.4280.88-0.1+3
NVDopensuse/leap15.1, 15.2+1

Also affects: Debian Linux 10.0, Fedora 31, 32, 33

Patches

🔴Vulnerability Details

3
GHSA
GHSA-p56m-hx7c-pjv5: Insufficient policy validation in extensions in Google Chrome prior to 852022-05-24
CVEList
CVE-2020-15961: Insufficient policy validation in extensions in Google Chrome prior to 852020-09-21
OSV
CVE-2020-15961: Insufficient policy validation in extensions in Google Chrome prior to 852020-09-21

📋Vendor Advisories

3
Red Hat
chromium-browser: Insufficient policy enforcement in extensions2020-09-21
Chrome
Stable Channel Update for Desktop: CVE-2020-159602020-09-21
Debian
CVE-2020-15961: chromium - Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183...2020

💬Community

3
Bugzilla
CVE-2020-15960 CVE-2020-15961 CVE-2020-15962 CVE-2020-15963 CVE-2020-15964 CVE-2020-15965 CVE-2020-15966 chromium: various flaws [epel-all]2020-09-22
Bugzilla
CVE-2020-15961 chromium-browser: Insufficient policy enforcement in extensions2020-09-22
Bugzilla
CVE-2020-15960 CVE-2020-15961 CVE-2020-15962 CVE-2020-15963 CVE-2020-15964 CVE-2020-15965 CVE-2020-15966 chromium: various flaws [fedora-all]2020-09-22
CVE-2020-15961 — Google Chrome vulnerability | cvebase