First published: Mon Apr 29 2019(Updated: )
A remote web page could inject arbitrary HTML code into the Oculus Browser UI, allowing an attacker to spoof UI and potentially execute code. This affects the Oculus Browser starting from version 5.2.7 until 5.7.11.
Credit: cve-assign@fb.com cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oculus Oculus Browser | >=5.2.7<=5.7.11 | |
>=5.2.7<=5.7.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-3562.
The title of this vulnerability is 'A remote web page could inject arbitrary HTML code into the Oculus Browser UI allowing an attacker t…'.
The affected software is Oculus Browser version 5.2.7 to 5.7.11.
The severity of CVE-2019-3562 is medium with a CVSS score of 6.1.
To fix CVE-2019-3562, update your Oculus Browser to version 5.7.11 or a later version.