CVE-2020-15959
chromium - security update
4.3
MEDIUM
CVSS 3.1
EPSS 1.2%
Description
Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user to enable logging to obtain potentially sensitive information from process memory via social engineering.
How to fix CVE-2020-15959
To remediate CVE-2020-15959, upgrade the affected package to a fixed version below.
- Debian/chromium—upgrade to 87.0.4280.88-0.1 or later
- —upgrade to 87.0.4280.88-0.4~deb10u1 or later
Is CVE-2020-15959 being exploited?
Low — EPSS is 1.2%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 87.0.4280.88-0.1
- from 0, < 87.0.4280.88-0.4~deb10u1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |