CVE-2019-13762 — Improper Locking in Google Chrome
Severity
3.3LOWNVD
EPSS
0.0%
top 90.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 10
Latest updateMay 24
Description
Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allowed a local attacker to spoof downloaded files via local code.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 1.8 | Impact: 1.4
Affected Packages6 packages
Also affects: Debian Linux 10.0, 9.0, Fedora 30, 31, Enterprise Linux 6.0
🔴Vulnerability Details
3GHSA▶
GHSA-j2vg-4hpf-83v7: Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79↗2022-05-24
OSV▶
CVE-2019-13762: Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79↗2019-12-10
CVEList▶
CVE-2019-13762: Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79↗2019-12-10