cbcvebase.
CVE-2020-6472
published 2020-05-21

CVE-2020-6472: Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious…

medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory or disk via a crafted Chrome Extension.

Affected

14 ranges
VendorProductVersion rangeFixed in
chromiumchromium>= 0 < 83.0.4103.83-183.0.4103.83-1
chromiumchromium>= 0 < 83.0.4103.83-183.0.4103.83-1
chromiumchromium>= 0 < 83.0.4103.83-183.0.4103.83-1
chromiumchromium>= 0 < 83.0.4103.83-183.0.4103.83-1
debianchromium< chromium 83.0.4103.83-1 (bookworm)chromium 83.0.4103.83-1 (bookworm)
debiandebian_linux
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
googlechrome< 83.0.4103.6183.0.4103.61
googlechrome>= unspecified < 83.0.4103.6183.0.4103.61
googlechrome_chrome
opensusebackports_sle
opensuseleap

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
osv6.5MEDIUM