CVE-2020-6438 PUBLISHED

Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension.

EPSS 0.69% · 71.8th percentile

Risk Scores

EPSS Score
0.69%
71.8th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSchromium-browser0, 61.0.3163.100-0ubuntu1.1378, 62.0.3202.62-0ubuntu0.17.10.1380
Ubuntu:16.04:LTSchromium-browser56.0.2924.76-0ubuntu0.16.04.1268, 63.0.3239.84-0ubuntu0.16.04.1, 73.0.3683.75-0ubuntu0.16.04.1

Timeline

References

Open in Interactive Console →