CVE-2019-13707Improper Input Validation in Google Chrome

Severity
5.5MEDIUMNVD
EPSS
0.2%
top 59.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 25
Latest updateMay 24

Description

Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local attacker to leak files via a crafted application.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5google/chromeunspecified78.0.3904.70
NVDgoogle/chrome< 78.0.3904.70
Debianchromium/chromium< 78.0.3904.87-1+3
NVDopensuse/backportssle-15

🔴Vulnerability Details

3
GHSA
GHSA-79jw-wrqv-5vh6: Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 782022-05-24
OSV
CVE-2019-13707: Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 782019-11-25
CVEList
CVE-2019-13707: Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 782019-11-25

📋Vendor Advisories

3
Chrome
Stable Channel Update for Desktop: CVE-2019-137072019-10-22
Red Hat
chromium-browser: File storage disclosure2019-10-22
Debian
CVE-2019-13707: chromium - Insufficient validation of untrusted input in intents in Google Chrome on Androi...2019

💬Community

3
Bugzilla
CVE-2019-13699 CVE-2019-13700 CVE-2019-13701 CVE-2019-13702 CVE-2019-13703 CVE-2019-13704 CVE-2019-13705 CVE-2019-13706 CVE-2019-13707 CVE-2019-13708 CVE-2019-13709 CVE-2019-13710 CVE-2019-13711 CVE-22019-10-23
Bugzilla
CVE-2019-13699 CVE-2019-13700 CVE-2019-13701 CVE-2019-13702 CVE-2019-13703 CVE-2019-13704 CVE-2019-13705 CVE-2019-13706 CVE-2019-13707 CVE-2019-13708 CVE-2019-13709 CVE-2019-13710 CVE-2019-13711 CVE-22019-10-23
Bugzilla
CVE-2019-13707 chromium-browser: File storage disclosure2019-10-23
CVE-2019-13707 — Improper Input Validation in Google | cvebase