6.5
CVSSv3

CVE-2019-5778

Published: 19/02/2019 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A missing case for handling special schemes in permission request checks in Extensions in Google Chrome before 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to bypass extension permission checks for privileged pages via a crafted Chrome Extension.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

debian debian linux 9.0

redhat enterprise linux desktop 6.0

redhat enterprise linux server 6.0

redhat enterprise linux workstation 6.0

fedoraproject fedora 29

fedoraproject fedora 30

Vendor Advisories

Synopsis Critical: chromium-browser security update Type/Severity Security Advisory: Critical Topic An update for chromium-browser is now available for Red Hat Enterprise Linux 6 SupplementaryRed Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scor ...
Several vulnerabilities have been discovered in the chromium web browser CVE-2018-17481 A use-after-free issue was discovered in the pdfium library CVE-2019-5754 Klzgrad discovered an error in the QUIC networking implementation CVE-2019-5755 Jay Bosamiya discovered an implementation error in the v8 javascript library CVE-2019-5 ...
An insufficient policy enforcement issue has been found in the Extensions component of the chromium browser before 720362681 ...
The Chrome team is delighted to announce the promotion of Chrome 72 to the stable channel for Windows, Mac and Linux This will roll out over the coming days/weeks Chrome 720362681 contains a number of fixes and improvements -- a list of changes is available in the log Watch out for upcoming Chrome and Chromium blog po ...