CVE-2020-15966 — Google Chrome vulnerability
10 documents8 sources
Severity
4.3MEDIUMNVD
EPSS
0.9%
top 24.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 21
Latest updateMay 24
Description
Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4
Affected Packages5 packages
Also affects: Debian Linux 10.0, Fedora 31, 32, 33
Patches
🔴Vulnerability Details
3GHSA▶
GHSA-j2m6-qgr7-3354: Insufficient policy enforcement in extensions in Google Chrome prior to 85↗2022-05-24
CVEList▶
CVE-2020-15966: Insufficient policy enforcement in extensions in Google Chrome prior to 85↗2020-09-21
OSV▶
CVE-2020-15966: Insufficient policy enforcement in extensions in Google Chrome prior to 85↗2020-09-21
📋Vendor Advisories
3💬Community
3Bugzilla▶
CVE-2020-15960 CVE-2020-15961 CVE-2020-15962 CVE-2020-15963 CVE-2020-15964 CVE-2020-15965 CVE-2020-15966 chromium: various flaws [epel-all]↗2020-09-22
Bugzilla▶
CVE-2020-15960 CVE-2020-15961 CVE-2020-15962 CVE-2020-15963 CVE-2020-15964 CVE-2020-15965 CVE-2020-15966 chromium: various flaws [fedora-all]↗2020-09-22