Out-of-bounds read in Google Chrome - CVE-2020-6555

 

Out-of-bounds read in Google Chrome - CVE-2020-6555

Published: August 10, 2020 / Updated: October 13, 2020


Vulnerability identifier: #VU42559
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/U:Green
CVE-ID: CVE-2020-6555
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Affected software:
Google Chrome
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Fedora
SUSE Linux
Opensuse
chromium (Debian package)
chromium-browser (Red Hat package)
chromium

Detailed vulnerability description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the WebGL component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.


How to mitigate CVE-2020-6555

Update to version 84.0.4147.125.

Sources