Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Zihan Zheng

#44795of 53,633
5.8Total CVSS
Vulnerabilities · 1
PT-2020-2024
5.8
2020-02-04
Google · Google Chrome · CVE-2020-6412
**Name of the Vulnerable Software and Affected Versions** Google Chrome versions prior to 80.0.3987.87 **Description** The issue is related to insufficient validation of untrusted input in the Omnibox feature of Google Chrome. This could allow a remote attacker to perform domain spoofing via IDN homographs using a specially crafted domain name, potentially leading to unauthorized access to information and disruption of its integrity. **Recommendations** For Google Chrome versions prior to 80.0.3987.87, update to version 80.0.3987.87 or later to resolve the issue. As a temporary workaround, consider avoiding the use of potentially vulnerable domain names until the update is applied. Restrict access to untrusted input in the Omnibox to minimize the risk of exploitation.