CVE-2019-5864Improper Input Validation in Google Chrome

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 78.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 25
Latest updateMay 24

Description

Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

CVEListV5google/chromeunspecified76.0.3809.87
NVDgoogle/chrome< 76.0.3809.87
debiandebian/chromium< chromium 76.0.3809.87-1 (bookworm)
Debianchromium/chromium< 76.0.3809.87-1+3

🔴Vulnerability Details

2
GHSA
GHSA-rqw3-7f5v-7r6j: Insufficient data validation in CORS in Google Chrome prior to 762022-05-24
OSV
CVE-2019-5864: Insufficient data validation in CORS in Google Chrome prior to 762019-11-25

📋Vendor Advisories

2
Red Hat
chromium-browser: Insufficient port filtering in CORS for extensions2019-07-30
Debian
CVE-2019-5864: chromium - Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allo...2019

💬Community

3
Bugzilla
CVE-2019-5864 chromium-browser: Insufficient port filtering in CORS for extensions2019-08-06
Bugzilla
CVE-2019-5850 CVE-2019-5851 CVE-2019-5852 CVE-2019-5853 CVE-2019-5854 CVE-2019-5855 CVE-2019-5856 CVE-2019-5857 CVE-2019-5858 CVE-2019-5859 CVE-2019-5860 CVE-2019-5861 CVE-2019-5862 CVE-2019-5864 CVE-2019-08-01
Bugzilla
CVE-2019-5850 CVE-2019-5851 CVE-2019-5852 CVE-2019-5853 CVE-2019-5854 CVE-2019-5855 CVE-2019-5856 CVE-2019-5857 CVE-2019-5858 CVE-2019-5859 CVE-2019-5860 CVE-2019-5861 CVE-2019-5862 CVE-2019-5864 CVE-2019-08-01