First published: Mon Nov 25 2019(Updated: )
Insufficient policy enforcement in extensions in Google Chrome prior to 78.0.3904.70 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome (Trace Event) | <78.0.3904.70 | |
SUSE Backports | =sle-15-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13705 is a vulnerability in Google Chrome that allows an attacker to leak cross-origin data via a malicious extension.
The severity of CVE-2019-13705 is medium with a CVSS score of 4.3.
CVE-2019-13705 can be exploited by convincing a user to install a malicious extension on their Google Chrome browser.
Google Chrome versions prior to 78.0.3904.70 are affected by CVE-2019-13705.
To fix CVE-2019-13705, update your Google Chrome browser to version 78.0.3904.70 or newer.