vendor:
Google Chrome
by:
Cem Onat Karagun of Diesec GmBH
8.8
CVSS
HIGH
Heap-Corruption Remote Denial of Service
119
CWE
Product Name: Google Chrome
Affected Version From: Google Chrome 80.0.3987.87
Affected Version To: Google Chrome 80.0.3987.87
Patch Exists: YES
Related CWE: CVE-2020-6404
CPE: a:google:chrome
Metasploit:
https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2020-6404/, https://www.rapid7.com/db/vulnerabilities/microsoft-edge-cve-2020-6404/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2020-6404/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2020-6404/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2020-6404/, https://www.rapid7.com/db/vulnerabilities/google-chrome-cve-2020-6404/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2020-6404/
Other Scripts:
N/A
Platforms Tested: Windows x64 / Linux Debian x64 / MacOS
2020
Google Chrome 80.0.3987.87 – Heap-Corruption Remote Denial of Service (PoC)
A vulnerability in Google Chrome 80.0.3987.87 allows a remote attacker to cause a denial of service (DoS) condition by exploiting a heap-corruption vulnerability. The vulnerability is due to improper validation of user-supplied input by the affected software. An attacker can exploit this vulnerability by sending a specially crafted request to the affected software. Successful exploitation of this vulnerability could allow an attacker to cause a denial of service condition.
Mitigation:
Google has released a patch to address this vulnerability. Users are advised to update to the latest version of Google Chrome.