First published: Mon Nov 25 2019(Updated: )
Insufficient policy enforcement in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <78.0.3904.70 | |
openSUSE Backports | =15.0-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13704 has been classified with a high severity level due to its potential impact on security policies.
To remediate CVE-2019-13704, update Google Chrome to version 78.0.3904.70 or later.
CVE-2019-13704 affects users of Google Chrome versions prior to 78.0.3904.70 and openSUSE Backports 15.0-sp1.
CVE-2019-13704 is an insufficient policy enforcement vulnerability that allows attackers to bypass content security policies.
There are no recommended workarounds for CVE-2019-13704; the best course of action is to apply the necessary updates.