PT-2020-6449 · Google+2 · Google Chrome+2

Published

2020-03-31

·

Updated

2021-07-21

·

CVE-2020-6453

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 80.0.3987.162
Description The issue is caused by a buffer overflow in the dynamic memory of the V8 JavaScript engine handler in Google Chrome. This could allow a remote attacker to exploit heap corruption via a specially crafted HTML page, potentially impacting the confidentiality, integrity, and availability of protected information.
Recommendations For versions prior to 80.0.3987.162, update to version 80.0.3987.162 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially vulnerable HTML pages until the update is applied.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1706
ALT-PU-2020-1765
ALT-PU-2020-2420
ALT-PU-2020-2441
BDU:2021-04927
CVE-2020-6453
DSA-4654-1
RHSA-2020:1350
RHSA-2020_1350

Affected Products

Alt Linux
Google Chrome
Red Hat