CVE-2020-6460: Medium severity google chrome vulnerability
Insufficient data validation in URL formatting in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to perform domain spoofing via a crafted domain name.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-6460?
CVE-2020-6460 is a vulnerability in Google Chrome that allows a remote attacker to perform domain spoofing via a crafted domain name.
What is the severity of CVE-2020-6460?
The severity of CVE-2020-6460 is medium, with a severity value of 6.5.
Which software versions are affected by CVE-2020-6460?
Google Chrome versions prior to 81.0.4044.122 and Debian Linux 9.0 and 10.0 are affected by CVE-2020-6460.
How can I fix CVE-2020-6460?
Update Google Chrome to version 81.0.4044.122 or later, or apply the security patches provided by Debian Linux.
Where can I find more information about CVE-2020-6460?
You can find more information about CVE-2020-6460 at the following references: [Google Chrome Releases](https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_21.html), [Chromium Bug Tracker](https://crbug.com/1063566), [Debian Security Advisory](https://www.debian.org/security/2020/dsa-4714).