CVE-2020-6536
published 2020-07-22CVE-2020-6536: Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had persuaded the user to install a PWA to spoof the…
PriorityP420medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
1.42%
69.8th percentile
Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had persuaded the user to install a PWA to spoof the contents of the Omnibox (URL bar) via a crafted PWA.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 87.0.4280.88-0.1 | 87.0.4280.88-0.1 |
| chromium | chromium | >= 0 < 87.0.4280.88-0.1 | 87.0.4280.88-0.1 |
| chromium | chromium | >= 0 < 87.0.4280.88-0.1 | 87.0.4280.88-0.1 |
| chromium | chromium | >= 0 < 87.0.4280.88-0.1 | 87.0.4280.88-0.1 |
| debian | chromium | < chromium 87.0.4280.88-0.1 (bookworm) | chromium 87.0.4280.88-0.1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome | < 84.0.4147.89 | 84.0.4147.89 | |
| chrome | >= unspecified < 84.0.4147.89 | 84.0.4147.89 | |
| chrome_chrome | — | — | |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6qmw-fm65-3cg3: Incorrect security UI in PWAs in Google Chrome prior to 84
ghsa_unreviewed·2022-05-24
CVE-2020-6536 [MEDIUM] GHSA-6qmw-fm65-3cg3: Incorrect security UI in PWAs in Google Chrome prior to 84
Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had persuaded the user to install a PWA to spoof the contents of the Omnibox (URL bar) via a crafted PWA.
OSV
CVE-2020-6536: Incorrect security UI in PWAs in Google Chrome prior to 84
osv·2020-07-22·CVSS 4.3
CVE-2020-6536 [MEDIUM] CVE-2020-6536: Incorrect security UI in PWAs in Google Chrome prior to 84
Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had persuaded the user to install a PWA to spoof the contents of the Omnibox (URL bar) via a crafted PWA.
Chrome
Stable Channel Update for Desktop: CVE-2020-6535
vendor_chrome·2020-07-14·CVSS 6.1
CVE-2020-6535 [LOW] Stable Channel Update for Desktop: CVE-2020-6535
Stable Channel Update for Desktop
CVE-2020-6535: Insufficient data validation in WebUI. Reported by Jun Kokatsu, Microsoft Browser Vulnerability Research on 2020-04-22
[$TBD][ 1080934 ] Low CVE-2020-6536: Incorrect security UI in PWAs
Reported by Zhiyang Zeng(@Wester) of OPPO ZIWU Cyber Security Lab on 2020-05-09
Severity: low
Red Hat
chromium-browser: Incorrect security UI in PWAs
vendor_redhat·2020-07-14·CVSS 4.3
CVE-2020-6536 [MEDIUM] chromium-browser: Incorrect security UI in PWAs
chromium-browser: Incorrect security UI in PWAs
Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had persuaded the user to install a PWA to spoof the contents of the Omnibox (URL bar) via a crafted PWA.
Debian
CVE-2020-6536: chromium - Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a r...
vendor_debian·2020·CVSS 4.3
CVE-2020-6536 [MEDIUM] CVE-2020-6536: chromium - Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a r...
Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had persuaded the user to install a PWA to spoof the contents of the Omnibox (URL bar) via a crafted PWA.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved (fixed in 87.0.4280.88-0.1)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00069.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00041.htmlhttps://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.htmlhttps://crbug.com/1080934https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MTRPPTKZ2RKVH2XGQCWNFZ7FOGQ5LLCA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MYIDWCHG24ZTFD4P42D4A4WWPPA74BCG/https://security.gentoo.org/glsa/202007-08https://www.debian.org/security/2021/dsa-4824http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00069.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00041.htmlhttps://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.htmlhttps://crbug.com/1080934https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MTRPPTKZ2RKVH2XGQCWNFZ7FOGQ5LLCA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MYIDWCHG24ZTFD4P42D4A4WWPPA74BCG/https://security.gentoo.org/glsa/202007-08https://www.debian.org/security/2021/dsa-4824
2020-07-22
Published