PT-2020-4258 · Google · Google Chrome

Rayyan Bijoora

·

Published

2020-06-03

·

Updated

2022-10-14

·

CVE-2020-6497

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions: Google Chrome on iOS versions prior to 83.0.4103.88
Description: The issue is related to insufficient policy enforcement in the Omnibox component of Google Chrome on iOS, allowing a remote attacker to perform domain spoofing via a crafted URI. This could potentially impact the integrity of protected information.
Recommendations: For Google Chrome on iOS versions prior to 83.0.4103.88, update to version 83.0.4103.88 or later to resolve the issue.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

BDU:2020-04722
CVE-2020-6497
DSA-4714-1
DSA-4714-2
DSA-4714-3

Affected Products

Google Chrome