CVE-2019-5879Incorrect Authorization in Google Chrome

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 70.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 25
Latest updateMay 24

Description

Insufficient policy enforcement in extensions in Google Chrome prior to 77.0.3865.75 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5google/chromeunspecified77.0.3865.75
NVDgoogle/chrome< 77.0.3865.75
debiandebian/chromium< chromium 78.0.3904.87-1 (bookworm)
Debianchromium/chromium< 78.0.3904.87-1+3

🔴Vulnerability Details

2
GHSA
GHSA-hcrx-7wpm-hhwq: Insufficient policy enforcement in extensions in Google Chrome prior to 772022-05-24
OSV
CVE-2019-5879: Insufficient policy enforcement in extensions in Google Chrome prior to 772019-11-25

📋Vendor Advisories

2
Red Hat
chromium-browser: Extensions can read some local files2019-09-10
Debian
CVE-2019-5879: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 77.0.386...2019

💬Community

1
Bugzilla
CVE-2019-5879 chromium-browser: Extensions can read some local files2019-10-16