Insufficient policy enforcement in CORS in Google Chrome prior to 80.0.3987.87 allowed a local attacker to obtain potentially sensitive information via a crafted HTML page.
References
Information
Published : 2020-02-11 15:15
Updated : 2021-07-21 11:39
NVD link : CVE-2020-6408
Mitre link : CVE-2020-6408
JSON object : View
Products Affected
- chrome
opensuse
- backports_sle
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
