First published: Mon Nov 25 2019(Updated: )
Insufficient policy enforcement in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <78.0.3904.70 | |
openSUSE Backports | =15.0-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13709 has been classified as a high-severity vulnerability due to its potential to allow remote attackers to bypass download restrictions.
To fix CVE-2019-13709, update Google Chrome to version 78.0.3904.70 or later.
Users of Google Chrome versions prior to 78.0.3904.70 are affected by CVE-2019-13709.
CVE-2019-13709 facilitates an attack that allows remote users to bypass download restrictions through a crafted HTML page.
No specific workarounds are recommended for CVE-2019-13709; updating to the latest version of the browser is advised.