CVE-2020-6440

10 documents8 sources
Severity
4.3MEDIUM
EPSS
0.7%
top 28.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 13
Latest updateMay 24

Description

Inappropriate implementation in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

CVEListV5google/chromeunspecified81.0.4044.92
NVDgoogle/chrome< 81.0.4044.92
Debianchromium< 81.0.4044.92-1+3
NVDopensuse/leap15.1
NVDopensuse/backportssle-15

Also affects: Debian Linux 10.0, 9.0, Fedora 30, 31, 32

🔴Vulnerability Details

3
GHSA
GHSA-vc2r-f7w9-m9hp: Inappropriate implementation in extensions in Google Chrome prior to 812022-05-24
CVEList
CVE-2020-6440: Inappropriate implementation in extensions in Google Chrome prior to 812020-04-13
OSV
CVE-2020-6440: Inappropriate implementation in extensions in Google Chrome prior to 812020-04-13

📋Vendor Advisories

3
Red Hat
chromium-browser: Inappropriate implementation in extensions2020-04-07
Chrome
Stable Channel Update for Desktop: CVE-2020-64392020-04-07
Debian
CVE-2020-6440: chromium - Inappropriate implementation in extensions in Google Chrome prior to 81.0.4044.9...2020

💬Community

3
Bugzilla
CVE-2020-6423 CVE-2020-6430 CVE-2020-6431 CVE-2020-6433 CVE-2020-6434 CVE-2020-6435 CVE-2020-6436 CVE-2020-6437 CVE-2020-6438 CVE-2020-6439 CVE-2020-6440 CVE-2020-6441 CVE-2020-6442 CVE-2020-6443 CVE-2020-04-09
Bugzilla
CVE-2020-6440 chromium-browser: Inappropriate implementation in extensions2020-04-09
Bugzilla
CVE-2020-6423 CVE-2020-6430 CVE-2020-6431 CVE-2020-6433 CVE-2020-6434 CVE-2020-6435 CVE-2020-6436 CVE-2020-6437 CVE-2020-6438 CVE-2020-6439 CVE-2020-6440 CVE-2020-6441 CVE-2020-6442 CVE-2020-6443 CVE-2020-04-09
CVE-2020-6440 (MEDIUM CVSS 4.3) | Inappropriate implementation in ext | cvebase.io