CVE-2019-13748
Severity
6.5MEDIUM
EPSS
0.8%
top 25.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 10
Latest updateMay 24
Description
Insufficient policy enforcement in developer tools in Google Chrome prior to 79.0.3945.79 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6
Affected Packages6 packages
Also affects: Debian Linux 10.0, 9.0, Fedora 30, 31, Enterprise Linux 6.0
Patches
🔴Vulnerability Details
3GHSA▶
GHSA-vxmp-6cq6-c2x9: Insufficient policy enforcement in developer tools in Google Chrome prior to 79↗2022-05-24
CVEList▶
CVE-2019-13748: Insufficient policy enforcement in developer tools in Google Chrome prior to 79↗2019-12-10
OSV▶
CVE-2019-13748: Insufficient policy enforcement in developer tools in Google Chrome prior to 79↗2019-12-10
📋Vendor Advisories
3💬Community
1Bugzilla
▶