chromereleases.googleblog.com
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html CVE-2020-6572
HIGHCISA KEV
Google Chrome Media Use-After-Free Vulnerability
Record summary
CVE-2020-6572 has a selected CVSS score of 8.8 (high). CISA lists CVE-2020-6572 in KEV.
Description
Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Jan 10, 2022 · CISA
- VulnCheck KEV
- Listed · Apr 1, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 4, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
ChromeBrowse Google / Chrome | CVE List | Before 81.0.4044.92 | affected |
Chrome MediaBrowse Google / Chrome Media | CISA | Version data not supplied | |
References
4crbug.com
https://crbug.com/1066893 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-6572 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-6572