CVE-2020-6501: Google Chrome

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.

Affected products

  • Google Chrome: before 80.0.3987.87 (fixed in 80.0.3987.87)

Published 2020-06-03. Last modified 2026-06-17.