CVE-2020-6438Information Exposure via Error Message in Google Chrome

Severity
4.3MEDIUMNVD
EPSS
0.7%
top 28.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 13
Latest updateMay 24

Description

Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

CVEListV5google/chromeunspecified81.0.4044.92
NVDgoogle/chrome< 81.0.4044.92
Debianchromium/chromium< 81.0.4044.92-1+3
NVDopensuse/leap15.1

Also affects: Debian Linux 10.0, 9.0, Fedora 30, 31, 32

🔴Vulnerability Details

3
GHSA
GHSA-vv9m-mjhj-9cqc: Insufficient policy enforcement in extensions in Google Chrome prior to 812022-05-24
CVEList
CVE-2020-6438: Insufficient policy enforcement in extensions in Google Chrome prior to 812020-04-13
OSV
CVE-2020-6438: Insufficient policy enforcement in extensions in Google Chrome prior to 812020-04-13

📋Vendor Advisories

3
Red Hat
chromium-browser: Insufficient policy enforcement in extensions2020-04-07
Chrome
Stable Channel Update for Desktop: CVE-2020-64372020-04-07
Debian
CVE-2020-6438: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.404...2020

💬Community

3
Bugzilla
CVE-2020-6423 CVE-2020-6430 CVE-2020-6431 CVE-2020-6433 CVE-2020-6434 CVE-2020-6435 CVE-2020-6436 CVE-2020-6437 CVE-2020-6438 CVE-2020-6439 CVE-2020-6440 CVE-2020-6441 CVE-2020-6442 CVE-2020-6443 CVE-2020-04-09
Bugzilla
CVE-2020-6438 chromium-browser: Insufficient policy enforcement in extensions2020-04-09
Bugzilla
CVE-2020-6423 CVE-2020-6430 CVE-2020-6431 CVE-2020-6433 CVE-2020-6434 CVE-2020-6435 CVE-2020-6436 CVE-2020-6437 CVE-2020-6438 CVE-2020-6439 CVE-2020-6440 CVE-2020-6441 CVE-2020-6442 CVE-2020-6443 CVE-2020-04-09
CVE-2020-6438 — Information Exposure via Error Message | cvebase