PT-2019-2917 · Google+3 · Google Chrome+3
Published
2019-07-30
·
Updated
2024-06-15
·
CVE-2019-5864
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 76.0.3809.87
Description
The issue is related to insufficient data validation in CORS, allowing an attacker to bypass content security policy. This can be achieved by convincing a user to install a malicious extension or through a specially crafted web page, enabling a remote attacker to circumvent existing security restrictions.
Recommendations
For versions prior to 76.0.3809.87, update to version 76.0.3809.87 or later to resolve the issue.
Exploit
Fix
Improper Access Control
RCE
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Google Chrome
Red Hat
Suse