CVE-2020-15966Google Chrome vulnerability

10 documents8 sources
Severity
4.3MEDIUMNVD
EPSS
0.9%
top 24.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 21
Latest updateMay 24

Description

Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

CVEListV5google/chromeunspecified85.0.4183.121
NVDgoogle/chrome< 85.0.4183.121
Debianchromium/chromium< 87.0.4280.88-0.1+3
NVDopensuse/leap15.1, 15.2+1

Also affects: Debian Linux 10.0, Fedora 31, 32, 33

Patches

🔴Vulnerability Details

3
GHSA
GHSA-j2m6-qgr7-3354: Insufficient policy enforcement in extensions in Google Chrome prior to 852022-05-24
CVEList
CVE-2020-15966: Insufficient policy enforcement in extensions in Google Chrome prior to 852020-09-21
OSV
CVE-2020-15966: Insufficient policy enforcement in extensions in Google Chrome prior to 852020-09-21

📋Vendor Advisories

3
Red Hat
chromium-browser: Insufficient policy enforcement in extensions2020-09-21
Chrome
Stable Channel Update for Desktop: CVE-2020-159632020-09-21
Debian
CVE-2020-15966: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.418...2020

💬Community

3
Bugzilla
CVE-2020-15966 chromium-browser: Insufficient policy enforcement in extensions2020-09-22
Bugzilla
CVE-2020-15960 CVE-2020-15961 CVE-2020-15962 CVE-2020-15963 CVE-2020-15964 CVE-2020-15965 CVE-2020-15966 chromium: various flaws [epel-all]2020-09-22
Bugzilla
CVE-2020-15960 CVE-2020-15961 CVE-2020-15962 CVE-2020-15963 CVE-2020-15964 CVE-2020-15965 CVE-2020-15966 chromium: various flaws [fedora-all]2020-09-22
CVE-2020-15966 — Google Chrome vulnerability | cvebase