CVE-2019-5838Incorrect Authorization in Google Chrome

Severity
4.3MEDIUMNVD
EPSS
0.5%
top 35.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 27
Latest updateMay 24

Description

Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed an attacker who convinced a user to install a malicious extension to bypass restrictions on file URIs via a crafted Chrome Extension.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

CVEListV5google/chromeunspecified75.0.3770.80
NVDgoogle/chrome< 75.0.3770.80
Debianchromium/chromium< 75.0.3770.80-1+3
NVDopensuse/leap15.0, 15.1, 42.3+2
NVDopensuse/backportssle-15

Also affects: Debian Linux 10.0, Fedora 29, 30

🔴Vulnerability Details

3
GHSA
GHSA-h7hj-53wf-rwww: Insufficient policy enforcement in extensions API in Google Chrome prior to 752022-05-24
CVEList
CVE-2019-5838: Insufficient policy enforcement in extensions API in Google Chrome prior to 752019-06-27
OSV
CVE-2019-5838: Insufficient policy enforcement in extensions API in Google Chrome prior to 752019-06-27

📋Vendor Advisories

2
Red Hat
chromium-browser: Overly permissive tab access in Extensions2019-06-04
Debian
CVE-2019-5838: chromium - Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0...2019

💬Community

3
Bugzilla
CVE-2019-5838 chromium-browser: Overly permissive tab access in Extensions2019-06-07
Bugzilla
CVE-2019-5828 CVE-2019-5829 CVE-2019-5830 CVE-2019-5831 CVE-2019-5832 CVE-2019-5833 CVE-2019-5834 CVE-2019-5835 CVE-2019-5836 CVE-2019-5837 CVE-2019-5838 CVE-2019-5839 CVE-2019-5840 chromium: various 2019-06-07
Bugzilla
CVE-2019-5828 CVE-2019-5829 CVE-2019-5830 CVE-2019-5831 CVE-2019-5832 CVE-2019-5833 CVE-2019-5834 CVE-2019-5835 CVE-2019-5836 CVE-2019-5837 CVE-2019-5838 CVE-2019-5839 CVE-2019-5840 chromium: various 2019-06-07
CVE-2019-5838 — Incorrect Authorization in Google | cvebase