First published: Mon Jan 13 2020(Updated: )
XSS in the Video Downloader component before 1.5 of Avast Secure Browser 77.1.1831.91 and AVG Secure Browser 77.0.1790.77 allows websites to execute their code in the context of this component. While Video Downloader is technically a browser extension, it is granted a very wide set of privileges and can for example access cookies and browsing history, spy on the user while they are surfing the web, and alter their surfing experience in almost arbitrary ways.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Avast Secure Browser | =77.1.1831.91 | |
AVG Secure Browser | =77.0.1790.77 | |
Video Downloader Project Video Downloader | <1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this XSS vulnerability is CVE-2019-18893.
The severity level of CVE-2019-18893 is medium.
The Avast Secure Browser versions 77.1.1831.91 and AVG Secure Browser version 77.0.1790.77 are affected by CVE-2019-18893.
CVE-2019-18893 allows websites to execute their code in the context of the Video Downloader component.
You can find more information about CVE-2019-18893 at the following link: https://palant.de/2020/01/13/pwning-avast-secure-browser-for-fun-and-profit/