Spoofing attack in Google Chrome - CVE-2019-13701

 

Spoofing attack in Google Chrome - CVE-2019-13701

Published: October 23, 2019


Vulnerability identifier: #VU22215
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13701
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to incorrect processing of user-supplied data. A remote attacker can create a specially crafted webpage and spoof browser URL in navigation.


Affected software

Google Chrome
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Opensuse
SUSE Linux

How to mitigate CVE-2019-13701

Install updates from vendor's website.

Google Chrome - update to 78.0.3904.70

External References

Related Security Bulletins