CVE-2020-6568Google Chrome vulnerability

10 documents8 sources
Severity
6.5MEDIUMNVD
EPSS
0.5%
top 32.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 21
Latest updateMay 24

Description

Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5google/chromeunspecified85.0.4183.83
NVDgoogle/chrome< 85.0.4183.83
Debianchromium/chromium< 87.0.4280.88-0.1+3
NVDopensuse/leap15.1, 15.2+1

Also affects: Debian Linux 10.0, Fedora 33

Patches

🔴Vulnerability Details

3
GHSA
GHSA-6w6q-2f3j-fg92: Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 852022-05-24
CVEList
CVE-2020-6568: Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 852020-09-21
OSV
CVE-2020-6568: Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 852020-09-21

📋Vendor Advisories

3
Red Hat
chromium-browser: Insufficient policy enforcement in intent handling2020-08-25
Chrome
Stable Channel Update for Desktop: CVE-2020-65662020-08-25
Debian
CVE-2020-6568: chromium - Insufficient policy enforcement in intent handling in Google Chrome on Android p...2020

💬Community

3
Bugzilla
CVE-2020-6568 chromium-browser: Insufficient policy enforcement in intent handling2020-08-27
Bugzilla
CVE-2020-6559 CVE-2020-6560 CVE-2020-6561 CVE-2020-6562 CVE-2020-6563 CVE-2020-6564 CVE-2020-6565 CVE-2020-6566 CVE-2020-6567 CVE-2020-6568 CVE-2020-6569 CVE-2020-6570 CVE-2020-6571 chromium: various 2020-08-27
Bugzilla
CVE-2020-6559 CVE-2020-6560 CVE-2020-6561 CVE-2020-6562 CVE-2020-6563 CVE-2020-6564 CVE-2020-6565 CVE-2020-6566 CVE-2020-6567 CVE-2020-6568 CVE-2020-6569 CVE-2020-6570 CVE-2020-6571 chromium: various 2020-08-27
CVE-2020-6568 — Google Chrome vulnerability | cvebase