CVE-2020-6535 PUBLISHED

Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page.

EPSS 1.14% · 78.3th percentile

Risk Scores

EPSS Score
1.14%
78.3th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSchromium-browser0, 61.0.3163.100-0ubuntu1.1378, 62.0.3202.62-0ubuntu0.17.10.1380
Ubuntu:16.04:LTSchromium-browser71.0.3578.80-0ubuntu0.16.04.1, 71.0.3578.98-0ubuntu0.16.04.1, 72.0.3626.119-0ubuntu0.16.04.1

Timeline

References

Open in Interactive Console →