CVE-2020-6506

Description

Insufficient policy enforcement in WebView in Google Chrome on Android prior to 83.0.4103.106 allowed a remote attacker to bypass site isolation via a crafted HTML page.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
1.414

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2020-6505,CVE-2020-6506,CVE-2020-6507 are fixed in Google Chrome (x64) (83.0.4103.106)Windows
Vulnerabilities CVE-2020-6505,CVE-2020-6506,CVE-2020-6507 are fixed in Google Chrome (83.0.4103.106)Windows
Vulnerabilities CVE-2020-6505,CVE-2020-6506,CVE-2020-6507, CVE-2020-6506, CVE-2020-6507 are fixed in Microsoft Edge for business 83.0.478.53Windows
Vulnerabilities CVE-2020-6505,CVE-2020-6506,CVE-2020-6507 are fixed in Google Chrome For Mac (83.0.4103.106)Mac
chromium security update(DSA-4714-1) chromium_83.0.4103.116-1~deb10u1_amd64.debLinux
Vulnerabilities CVE-2020-6505,CVE-2020-6506,CVE-2020-6507 are fixed in Google Chrome (83.0.4103.106) (For Debian)Linux
Vulnerabilities CVE-2020-6505,CVE-2020-6506,CVE-2020-6507 are fixed in Google Chrome (83.0.4103.106) (For Centos)Linux
Vulnerabilities CVE-2020-6505,CVE-2020-6506,CVE-2020-6507 are fixed in Google Chrome (83.0.4103.106) (For RedHat)Linux
Vulnerabilities CVE-2020-6505,CVE-2020-6506,CVE-2020-6507 are fixed in Google Chrome (83.0.4103.106) (For Suse)Linux
Vulnerabilities CVE-2020-6505,CVE-2020-6506,CVE-2020-6507 are fixed in Google Chrome (83.0.4103.106) (For Ubuntu)Linux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-314662Google Chrome (x64) (83.0.4103.106)
PATCH-314661Google Chrome (83.0.4103.106)
PATCH-609673Google Chrome for Mac (132.0.6834.83, 132.0.6834.84)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234