Universal cross-site scripting in Google Chrome - CVE-2020-6506
Published: June 15, 2020 / Updated: October 1, 2020
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in the Google Chrome WebView system component. The vulnerability allows cross-origin iframes to execute arbitrary JavaScript in the top-level document.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Gentoo Linux
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Fedora
SUSE Linux
Opensuse
react-native-webview
chromium (Debian package)
chromium-browser (Red Hat package)
chromium (Alpine package)
chromium
How to mitigate CVE-2020-6506
chromium (Debian package) - update to 83.0.4103.116-1~deb10u1
chromium-browser (Red Hat package) - update to 83.0.4103.106-1.el6_10
chromium (Alpine package) - update to 83.0.4103.116-r0
chromium - addressed in versions 83.0.4103.106-1.el7, 83.0.4103.106-1.el8, 83.0.4103.106-1.fc31, 83.0.4103.106-1.fc32, 83.0.4103.116-3.el7, 83.0.4103.116-3.el8, 83.0.4103.116-3.fc31, 83.0.4103.116-3.fc32
External References
Related Security Bulletins
- Stable Channel Update for Desktop
- OpenSUSE Linux update for chromium
- OpenSUSE Linux update for chromium
- Red Hat Enterprise Linux 6 Supplementary update for chromium-browser
- OpenSUSE Linux update for chromium
- Debian update for chromium
- Gentoo update for Chromium, Google Chrome
- Permissions, Privileges, and Access Controls in chromium (Alpine package)
- Universal XSS in react-native-webview package
- Gentoo update for Qt WebEngine
- Fedora 31 update for chromium
- Fedora 32 update for chromium
- Fedora EPEL 7 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora 31 update for chromium
- Fedora 32 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora EPEL 7 update for chromium