PT-2020-5695 · Google+3 · Google Chrome+3

Published

2020-07-14

·

Updated

2024-06-15

·

CVE-2020-6536

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 84.0.4147.89
Description The issue concerns an incorrect security UI in Progressive Web Apps (PWAs) within Google Chrome, allowing a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted PWA. This is related to an incorrect security check for standard elements, potentially impacting data integrity.
Recommendations For versions prior to 84.0.4147.89, update to version 84.0.4147.89 or later to resolve the issue. As a temporary workaround, consider avoiding the installation of PWAs from untrusted sources until the update is applied.

Exploit

Fix

Improperly Implemented Security Check for Standard

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2453
ALT-PU-2020-2468
ALT-PU-2020-3144
ALT-PU-2021-1210
ALT-PU-2021-1379
BDU:2021-01504
CVE-2020-6536
DSA-4824-1
OPENSUSE-SU-2020:1020-1
OPENSUSE-SU-2020:1021-1
OPENSUSE-SU-2020:1048-1
OPENSUSE-SU-2020:1061-1
OPENSUSE-SU-2020:1148-1
OPENSUSE-SU-2020:1172-1
OPENSUSE-SU-2020_1020-1
OPENSUSE-SU-2020_1021-1
OPENSUSE-SU-2020_1148-1
OPENSUSE-SU-2020_1172-1
OPENSUSE-SU-2024:10681-1
OPENSUSE-SU-2024:12948-1
RHSA-2020:3377
RHSA-2020_3377

Affected Products

Alt Linux
Google Chrome
Red Hat
Suse