ZeroHour
Cisco Talospublished ()ingested

Vulnerability Spotlight: Information leak vulnerability in Google Chrome WebGL

highVulnerability exploited in the wildimportance 60CVE-2020-6555

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-6555
Out of bounds read in WebGL in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to obtain potentially sensitive information from process memory vi

Out of bounds read in WebGL in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

NVD description · AI analysis pending
7.62% PoC
  • google chrome
  • google debian linux
  • google fedora
Full article235 words · extracted from blog.talosintelligence.com · click to collapse

Tuesday, October 13, 2020 14:22

Marcin Towalski of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.

The Google Chrome web browser contains a vulnerability that could be exploited by an adversary to carry out a range of malicious actions. Chrome is one of the most popular web browsers currently available to users. Cisco Talos researchers recently discovered a bug in WebGL, which is a Chrome API responsible for displaying 3-D graphics.

In accordance with our coordinated disclosure policy, Cisco Talos worked with Google to ensure that these issues are resolved and that an update is available for affected customers.

Vulnerability details

Google Chrome DrawElementsInstanced information leak vulnerability (TALOS-2020-1123/CVE-2020-6555)

An information disclosure vulnerability exists in the WebGL functionality of Google Chrome 83.0.4103.116 (Stable) (64-bit) and 86.0.4198.0 (Developer Build) (64-bit). Specially crafted JavaScript can cause an out-of-bounds read. The victim must visit a specially crafted, malicious web page to trigger this vulnerability.

Read the complete vulnerability advisory here for additional information.

Versions tested

Talos tested and confirmed that Google Chrome, version 83.0.4103.61 and the developer build of Chrome version 86.0.4198.0 (64-bit) is affected by this vulnerability.

Coverage

The following SNORTⓇ rules will detect exploitation attempts. Note that additional rules may be released at a future date and current rules are subject to change pending additional vulnerability information. For the most current rule information, please refer to your Firepower Management Center or Snort.org.

Snort Rules: 54584, 54585

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/vuln-spotlight-chrome-web-gl-info-leak/