PT-2020-5756 · Google+3 · Google Chrome+3

Published

2020-08-25

·

Updated

2024-06-15

·

CVE-2020-6559

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Google Chrome versions prior to 85.0.4183.83
Description: The issue is related to a use after free error in the presentation API of Google Chrome, which can lead to heap corruption. This can potentially allow a remote attacker to access confidential data, compromise data integrity, and cause a denial of service.
Recommendations: For versions prior to 85.0.4183.83, update to version 85.0.4183.83 or later to resolve the issue. As a temporary workaround, consider restricting access to crafted HTML pages that could exploit the heap corruption via the presentation API until a patch is applied.

Exploit

Fix

Memory Corruption

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2743
ALT-PU-2020-3144
ALT-PU-2021-1157
ALT-PU-2021-1210
ALT-PU-2021-1379
BDU:2021-01712
CVE-2020-6559
DSA-4824-1
OPENSUSE-SU-2020:1306-1
OPENSUSE-SU-2020:1309-1
OPENSUSE-SU-2020:1322-1
OPENSUSE-SU-2020:1328-1
OPENSUSE-SU-2020:1499-1
OPENSUSE-SU-2020:1510-1
OPENSUSE-SU-2020:1514-1
OPENSUSE-SU-2020_1306-1
OPENSUSE-SU-2020_1309-1
OPENSUSE-SU-2020_1499-1
OPENSUSE-SU-2024:10681-1
OPENSUSE-SU-2024:12948-1
RHSA-2020:3723
RHSA-2020_3723

Affected Products

Alt Linux
Google Chrome
Red Hat
Suse