CVE-2019-25154: Critical severity google chrome (trace event) vulnerability
Published Jul 16, 2024
·Updated
Inappropriate implementation in iframe in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Affected Software
1 affected component
Google Chrome<77.0.3865.75
Event History
Jul 16, 2024
CVE Published
via MITRE·10:30 PM
Data Sourced
via MITRE·10:30 PM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-25154?
The severity of CVE-2019-25154 is classified as Medium.
2
What does CVE-2019-25154 affect?
CVE-2019-25154 affects Google Chrome versions prior to 77.0.3865.75.
3
How can CVE-2019-25154 be exploited?
CVE-2019-25154 can be exploited via a crafted HTML page that allows a remote attacker to potentially perform a sandbox escape.
4
How do I fix CVE-2019-25154?
To fix CVE-2019-25154, upgrade Google Chrome to version 77.0.3865.75 or later.
5
What are the potential risks of CVE-2019-25154?
The potential risks of CVE-2019-25154 include unauthorized access and exploitation of vulnerabilities due to sandbox escape.