
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-6535 is a security vulnerability discovered in Google Chrome's WebUI component prior to version 84.0.4147.89. The vulnerability was identified as insufficient data validation that allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page (NVD).
The vulnerability is classified as a Cross-site Scripting (CWE-79) issue with a CVSS v3.1 Base Score of 6.1 (MEDIUM) and vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. The vulnerability specifically affects the WebUI component of Google Chrome, requiring user interaction and compromised renderer process to exploit (NVD).
If successfully exploited, this vulnerability could allow an attacker who has already compromised the renderer process to perform script or HTML injection into privileged pages, potentially leading to unauthorized access to sensitive browser data or functionality (Chrome Release).
The vulnerability requires the attacker to first compromise the renderer process and then craft a specific HTML page to exploit the insufficient data validation in WebUI. User interaction is required for successful exploitation (NVD).
The vulnerability was patched in Google Chrome version 84.0.4147.89. Users and administrators should upgrade to this version or later to mitigate the risk. The fix was also distributed to various Linux distributions including Debian, Fedora, and OpenSUSE (Gentoo Advisory, Debian Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."