vendor:
Chromium
by:
Project Zero
6,5
CVSS
MEDIUM
Type Confusion Vulnerability
843
CWE
Product Name: Chromium
Affected Version From: Chromium version prior to 83.0.4103.106
Affected Version To: Chromium version 83.0.4103.106
Patch Exists: YES
Related CWE: CVE-2020-6519
CPE: a:google:chromium
Metasploit:
https://www.rapid7.com/db/vulnerabilities/google-chrome-cve-2020-6519/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2020-6519/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2020-6519/, https://www.rapid7.com/db/vulnerabilities/microsoft-edge-cve-2020-6519/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2020-6519/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2020-6519/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2020-6531/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2020-6534/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2020-6518/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2020-6520/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2020-6525/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2020-6533/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2020-6510/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2020-6517/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2020-6535/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2020-6516/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2020-6521/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2020-6522/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2020-6536/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2020-6523/, https://www.rapid7.com/db/?q=CVE-2020-6519&type=&page=2, https://www.rapid7.com/db/?q=CVE-2020-6519&type=&page=2
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2020
HTMLKeygenElement::shadowSelect() Type Confusion Vulnerability
The HTMLKeygenElement::shadowSelect() function in Chromium allows accessing (and modifying) userAgentShadowRoot from JavaScript. It blindly casts the first child of the userAgentShadowRoot to HTMLSelectElement without checking the Node type, which can lead to a type confusion vulnerability.
Mitigation:
Upgrade to the latest version of Chromium