Code Injection in Google Chrome - CVE-2019-13714

 

Code Injection in Google Chrome - CVE-2019-13714

Published: October 24, 2019


Vulnerability identifier: #VU22227
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13714
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary JavaScript code.

The vulnerability exists due to improper input validation when processing CSS files. A remote attacker can send create a specially crafted webpage and perform CSS injection attack.


Affected software

Google Chrome
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Opensuse
SUSE Linux

How to mitigate CVE-2019-13714

Install updates from vendor's website.

Google Chrome - update to 78.0.3904.70

External References

Related Security Bulletins