PT-2020-5667 · Google+3 · Google Chrome+3
Kaustubh Vats
·
Published
2020-07-14
·
Updated
2024-06-15
·
CVE-2020-6529
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 84.0.4147.89
Description
The issue is related to an inappropriate implementation in WebRTC, allowing an attacker in a privileged network position to leak cross-origin data via a crafted HTML page. It is also described as a vulnerability in the WebRTC technology implementation in Google Chrome, related to insufficient input validation, which can be exploited by a remote attacker to access confidential data.
Recommendations
For versions prior to 84.0.4147.89, update to version 84.0.4147.89 or later to resolve the issue. As a temporary workaround, consider restricting access to WebRTC functionality until the update is applied.
Exploit
Fix
Improper Certificate Validation
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Google Chrome
Red Hat
Suse