PT-2020-3395 · Google+3 · Google Chrome+3
Ng Yik Phang
·
Published
2020-04-07
·
Updated
2024-06-15
·
CVE-2020-6438
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 81.0.4044.92
Description
The issue is related to insufficient policy enforcement in extensions, allowing an attacker to obtain potentially sensitive information from process memory via a crafted Chrome Extension. This can happen if a user is convinced to install a malicious extension. The attacker, acting remotely, can exploit this to gain access to confidential data.
Recommendations
For versions prior to 81.0.4044.92, update to version 81.0.4044.92 or later to resolve the issue. As a temporary workaround, consider restricting the installation of extensions to only trusted sources until the update is applied.
Exploit
Fix
Information Disclosure
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Google Chrome
Red Hat
Suse