CVE-2020-6492Use After Free in Google Chrome

CWE-416Use After Free6 documents5 sources
Severity
9.6CRITICALNVD
EPSS
0.4%
top 39.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 2
Latest updateMay 24

Description

Use after free in ANGLE in Google Chrome prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HExploitability: 2.8 | Impact: 6.0

Affected Packages4 packages

CVEListV5google/chromeunspecified83.0.4103.97
NVDgoogle/chrome< 83.0.4103.97
debiandebian/chromium< chromium 83.0.4103.106-1 (bookworm)
Debianchromium/chromium< 83.0.4103.106-1+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-j7xw-9x43-vxfh: Use after free in ANGLE in Google Chrome prior to 832022-05-24
OSV
CVE-2020-6492: Use after free in ANGLE in Google Chrome prior to 832021-11-02

📋Vendor Advisories

1
Debian
CVE-2020-6492: chromium - Use after free in ANGLE in Google Chrome prior to 83.0.4103.97 allowed a remote ...2020

🕵️Threat Intelligence

2
Securelist
IT threat evolution Q3 2020. Non-mobile statistics2020-11-20
Securelist
IT threat evolution Q3 2020. Non-mobile statistics2020-11-20