CVE-2019-5773Origin Validation Error in Google Chrome

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 49.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 19
Latest updateMay 13

Description

Insufficient origin validation in IndexedDB in Google Chrome prior to 72.0.3626.81 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

CVEListV5google/chromeunspecified72.0.3626.81
NVDgoogle/chrome< 72.0.3626.81
Debianchromium/chromium< 72.0.3626.81-1+3

Also affects: Debian Linux 9.0, Fedora 29, 30

🔴Vulnerability Details

3
GHSA
GHSA-jxw6-9p2w-3jf9: Insufficient origin validation in IndexedDB in Google Chrome prior to 722022-05-13
CVEList
CVE-2019-5773: Insufficient origin validation in IndexedDB in Google Chrome prior to 722019-02-19
OSV
CVE-2019-5773: Insufficient origin validation in IndexedDB in Google Chrome prior to 722019-02-19

📋Vendor Advisories

2
Red Hat
chromium-browser: Insufficient data validation in IndexedDB2019-01-29
Debian
CVE-2019-5773: chromium - Insufficient origin validation in IndexedDB in Google Chrome prior to 72.0.3626....2019

💬Community

1
Bugzilla
CVE-2019-5773 chromium-browser: Insufficient data validation in IndexedDB2019-01-30
CVE-2019-5773 — Origin Validation Error in Google | cvebase