New Google Chrome 85 Update Patches Vulnerabilities Cybers Guards
Researcher David Erceg found the extension-related vulnerabilities, identified by Google as “insufficient policy compliance in extensions,” in August. Three bugs of this kind were identified: CVE-2020-15961, a high-severity vulnerability for which he won a $15,000 bug bounty; CVE-2020-15963, also a high-severity vulnerability for which he obtained $5,000; and CVE-2020-15966, which has been rated medium severity and has yet to be decided for the bug bounty. Erceg told that due to the fact that Google has not listed it in its release notes, he has not called the affected API because the bugs he identified all threaten a similar API made accessible to extensions....