CVE-2020-6380
CVE-2020-6380
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.2%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
11 Feb 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.130 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted Chrome Extension.
Affected products
Google · ChromeWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →