Permissions, Privileges, and Access Controls in Google Chrome - CVE-2019-13702

 

Permissions, Privileges, and Access Controls in Google Chrome - CVE-2019-13702

Published: October 23, 2019


Vulnerability identifier: #VU22216
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13702
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to unspecified error in the Installer component. A remote attacker can bypass certain security restrictions.


Affected software

Google Chrome
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Opensuse
SUSE Linux

How to mitigate CVE-2019-13702

Install updates from vendor's website.

Google Chrome - update to 78.0.3904.70

External References

Related Security Bulletins