CVE-2020-15978: Insufficient data validation in navigation
Insufficient data validation in navigation in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-15967
- CVE-2020-15968
- CVE-2020-15969
- CVE-2020-15970
- CVE-2020-15971
- CVE-2020-15972
- CVE-2020-15990
- CVE-2020-15991
- CVE-2020-15973
- CVE-2020-15974
- CVE-2020-15975
- CVE-2020-15976
- CVE-2020-6557
- CVE-2020-15977
- CVE-2020-15979
- CVE-2020-15980
- CVE-2020-15981
- CVE-2020-15982
- CVE-2020-15983
- CVE-2020-15984
- CVE-2020-15985
- CVE-2020-15986
- CVE-2020-15987
- CVE-2020-15992
- CVE-2020-15988
- CVE-2020-15989
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-15978.
What is the severity of CVE-2020-15978?
The severity of CVE-2020-15978 is high with a severity value of 8.8.
Which software is affected by CVE-2020-15978?
Google Chrome on Android prior to version 86.0.4240.75 and Debian Linux version 10.0 are affected by CVE-2020-15978.
How can a remote attacker exploit CVE-2020-15978?
A remote attacker who has compromised the renderer process can exploit CVE-2020-15978 by bypassing navigation restrictions via a crafted HTML page.
Where can I find more information about CVE-2020-15978?
You can find more information about CVE-2020-15978 at the following references: [1](http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00016.html), [2](https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html), [3](https://crbug.com/1116280).