CVE-2020-6528Incorrect Authorization in Google Chrome

Severity
4.3MEDIUMNVD
EPSS
1.7%
top 17.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 22
Latest updateMay 24

Description

Incorrect security UI in basic auth in Google Chrome on iOS prior to 84.0.4147.89 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

CVEListV5google/chromeunspecified84.0.4147.89
NVDgoogle/chrome< 84.0.4147.89
Debianchromium/chromium< 87.0.4280.88-0.1+3
NVDopensuse/leap15.1, 15.2+1

Also affects: Debian Linux 10.0, Fedora 31, 32

🔴Vulnerability Details

3
GHSA
GHSA-hf38-9jxh-8cg7: Incorrect security UI in basic auth in Google Chrome on iOS prior to 842022-05-24
OSV
CVE-2020-6528: Incorrect security UI in basic auth in Google Chrome on iOS prior to 842020-07-22
CVEList
CVE-2020-6528: Incorrect security UI in basic auth in Google Chrome on iOS prior to 842020-07-22

📋Vendor Advisories

3
Red Hat
chromium-browser: Incorrect security UI in basic auth2020-07-14
Chrome
Stable Channel Update for Desktop: CVE-2020-65282020-07-14
Debian
CVE-2020-6528: chromium - Incorrect security UI in basic auth in Google Chrome on iOS prior to 84.0.4147.8...2020

💬Community

1
Bugzilla
CVE-2020-6528 chromium-browser: Incorrect security UI in basic auth2020-07-15
CVE-2020-6528 — Incorrect Authorization in Google | cvebase