CVE-2019-13705Improper Privilege Management in Google Chrome

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 54.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 25
Latest updateMay 24

Description

Insufficient policy enforcement in extensions in Google Chrome prior to 78.0.3904.70 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

CVEListV5google/chromeunspecified78.0.3904.70
NVDgoogle/chrome< 78.0.3904.70
Debianchromium/chromium< 78.0.3904.87-1+3
NVDopensuse/backportssle-15

🔴Vulnerability Details

3
GHSA
GHSA-v376-h543-mfgr: Insufficient policy enforcement in extensions in Google Chrome prior to 782022-05-24
CVEList
CVE-2019-13705: Insufficient policy enforcement in extensions in Google Chrome prior to 782019-11-25
OSV
CVE-2019-13705: Insufficient policy enforcement in extensions in Google Chrome prior to 782019-11-25

📋Vendor Advisories

3
Chrome
Stable Channel Update for Desktop: CVE-2019-137052019-10-22
Red Hat
chromium-browser: Extension permission bypass2019-10-22
Debian
CVE-2019-13705: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 78.0.390...2019

💬Community

3
Bugzilla
CVE-2019-13705 chromium-browser: Extension permission bypass2019-10-23
Bugzilla
CVE-2019-13699 CVE-2019-13700 CVE-2019-13701 CVE-2019-13702 CVE-2019-13703 CVE-2019-13704 CVE-2019-13705 CVE-2019-13706 CVE-2019-13707 CVE-2019-13708 CVE-2019-13709 CVE-2019-13710 CVE-2019-13711 CVE-22019-10-23
Bugzilla
CVE-2019-13699 CVE-2019-13700 CVE-2019-13701 CVE-2019-13702 CVE-2019-13703 CVE-2019-13704 CVE-2019-13705 CVE-2019-13706 CVE-2019-13707 CVE-2019-13708 CVE-2019-13709 CVE-2019-13710 CVE-2019-13711 CVE-22019-10-23
CVE-2019-13705 — Improper Privilege Management | cvebase