CVE-2020-6553Use After Free in Google Chrome

Severity
8.8HIGHNVD
EPSS
1.6%
top 18.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 21
Latest updateMay 24

Description

Use after free in offline mode in Google Chrome on iOS prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages5 packages

CVEListV5google/chromeunspecified84.0.4147.125
NVDgoogle/chrome< 84.0.4147.125
debiandebian/chromium< chromium 87.0.4280.88-0.1 (bookworm)
Debianchromium/chromium< 87.0.4280.88-0.1+3

Also affects: Debian Linux 10.0, Fedora 33

🔴Vulnerability Details

2
GHSA
GHSA-mj5m-vqcr-c4pf: Use after free in offline mode in Google Chrome on iOS prior to 842022-05-24
OSV
CVE-2020-6553: Use after free in offline mode in Google Chrome on iOS prior to 842020-09-21

📋Vendor Advisories

3
Red Hat
chromium-browser: Use after free in offline mode2020-08-10
Chrome
Stable Channel Update for Desktop: CVE-2020-65522020-08-10
Debian
CVE-2020-6553: chromium - Use after free in offline mode in Google Chrome on iOS prior to 84.0.4147.125 al...2020

💬Community

3
Bugzilla
CVE-2020-6553 chromium-browser: Use after free in offline mode2020-08-11
Bugzilla
CVE-2020-6542 CVE-2020-6543 CVE-2020-6544 CVE-2020-6545 CVE-2020-6546 CVE-2020-6547 CVE-2020-6548 CVE-2020-6549 CVE-2020-6550 CVE-2020-6551 CVE-2020-6552 CVE-2020-6553 CVE-2020-6554 CVE-2020-6555 chro2020-08-11
Bugzilla
CVE-2020-6542 CVE-2020-6543 CVE-2020-6544 CVE-2020-6545 CVE-2020-6546 CVE-2020-6547 CVE-2020-6548 CVE-2020-6549 CVE-2020-6550 CVE-2020-6551 CVE-2020-6552 CVE-2020-6553 CVE-2020-6554 CVE-2020-6555 chro2020-08-11