CVE-2020-6392Cross-site Scripting in Google Chrome

Severity
4.3MEDIUMNVD
EPSS
1.3%
top 20.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 11
Latest updateMay 24

Description

Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages7 packages

CVEListV5google/chromeunspecified80.0.3987.87
NVDgoogle/chrome< 80.0.3987.87
Debianchromium/chromium< 80.0.3987.106-1+3

Also affects: Debian Linux 10.0, 9.0, Fedora 30, 31

Patches

🔴Vulnerability Details

3
GHSA
GHSA-64hg-wgfm-6c25: Insufficient policy enforcement in extensions in Google Chrome prior to 802022-05-24
CVEList
CVE-2020-6392: Insufficient policy enforcement in extensions in Google Chrome prior to 802020-02-11
OSV
CVE-2020-6392: Insufficient policy enforcement in extensions in Google Chrome prior to 802020-02-11

📋Vendor Advisories

3
Red Hat
chromium-browser: Insufficient policy enforcement in extensions2020-02-04
Chrome
Stable Channel Update for Desktop: CVE-2020-63912020-02-04
Debian
CVE-2020-6392: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.398...2020

💬Community

3
Bugzilla
CVE-2020-6381 CVE-2020-6382 CVE-2020-6385 CVE-2020-6387 CVE-2020-6388 CVE-2020-6389 CVE-2020-6390 CVE-2020-6391 CVE-2020-6392 CVE-2020-6393 CVE-2020-6394 CVE-2020-6395 CVE-2020-6396 CVE-2020-6397 CVE-2020-02-11
Bugzilla
CVE-2020-6381 CVE-2020-6382 CVE-2020-6385 CVE-2020-6387 CVE-2020-6388 CVE-2020-6389 CVE-2020-6390 CVE-2020-6391 CVE-2020-6392 CVE-2020-6393 CVE-2020-6394 CVE-2020-6395 CVE-2020-6396 CVE-2020-6397 CVE-2020-02-11
Bugzilla
CVE-2020-6392 chromium-browser: Insufficient policy enforcement in extensions2020-02-10
CVE-2020-6392 — Cross-site Scripting in Google Chrome | cvebase