CVE-2019-13684: Medium severity google chrome (trace event) vulnerability
Published Apr 28, 2018
·Updated
Inappropriate implementation in JavaScript in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Credit
Michael Smith (spinda.net)
Affected Software
2 affected componentsFixes available
Google Chrome<72.0.3626.81
72.0.3626.81
Google Chrome<72.0.3626.81
Event History
Apr 28, 2018
CVE Published
12:00 AM
Nov 25, 2019
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-5754
- CVE-2019-5782
- CVE-2019-5755
- CVE-2019-5756
- CVE-2019-5757
- CVE-2019-5758
- CVE-2019-5759
- CVE-2019-5760
- CVE-2019-5761
- CVE-2019-5762
- CVE-2019-5763
- CVE-2019-5764
- CVE-2019-13768
- CVE-2019-5765
- CVE-2019-5785
- CVE-2019-5766
- CVE-2019-5767
- CVE-2019-5768
- CVE-2019-5769
- CVE-2019-5770
- CVE-2019-5771
- CVE-2019-5772
- CVE-2019-5773
- CVE-2019-5774
- CVE-2019-5775
- CVE-2019-5776
- CVE-2019-5777
- CVE-2018-20073
- CVE-2019-5778
- CVE-2019-5779
- CVE-2019-5780
- CVE-2019-5783
- CVE-2019-5781
Frequently Asked Questions
1
What is the severity of CVE-2019-13684?
CVE-2019-13684 has been assigned a high severity rating due to the potential for cross-origin data leakage.
2
How do I fix CVE-2019-13684?
To fix CVE-2019-13684, users should update Google Chrome to version 72.0.3626.81 or later.
3
What types of attacks can exploit CVE-2019-13684?
CVE-2019-13684 can be exploited by remote attackers through a crafted HTML page to leak sensitive information.
4
Which versions of Google Chrome are affected by CVE-2019-13684?
Google Chrome versions prior to 72.0.3626.81 are affected by CVE-2019-13684.
5
Who is the vendor responsible for addressing CVE-2019-13684?
Google is responsible for addressing CVE-2019-13684 through updates to the Chrome browser.