CVE-2020-15959
Last modified
CVE-2020-15959 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user to enable logging to obtain potentially sensitive information from process memory via social engineering.. EPSS estimates a 1.24% chance of exploitation in the next 30 days.
Description
Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user to enable logging to obtain potentially sensitive information from process memory via social engineering.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Chrome | < 85.0.4183.102 | — | |
| Opensuse | Backports Sle | 15.0 | Sp1 |
| Opensuse | Leap | 15.1 | — |
| Opensuse | Leap | 15.2 | — |
| Fedoraproject | Fedora | 31 | — |
| Fedoraproject | Fedora | 33 | — |
| Debian | Debian Linux | 10.0 | — |
References
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00072.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00078.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00081.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00049.htmlMailing List, Third Party Advisory
- https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop.htmlRelease Notes, Vendor Advisory
- https://crbug.com/1122684Permissions Required, Vendor Advisory
- https://security.gentoo.org/glsa/202101-30Third Party Advisory
- https://www.debian.org/security/2021/dsa-4824Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00072.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00078.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00081.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00049.htmlMailing List, Third Party Advisory
- https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop.htmlRelease Notes, Vendor Advisory
- https://crbug.com/1122684Permissions Required, Vendor Advisory
- https://security.gentoo.org/glsa/202101-30Third Party Advisory
- https://www.debian.org/security/2021/dsa-4824Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-15959?
How severe is CVE-2020-15959?
How do I fix CVE-2020-15959?
Are you affected by CVE-2020-15959?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
