CVE-2019-5864

Name
CVE-2019-5864
Description
Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Vendor Advisory https://chromereleases.googleblog.com/2019/07/stable-channel-update-for-desktop_30.html
Exploit https://crbug.com/936900

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* chrome >= None < 76.0.3809.87

Vulnerable and fixed packages

Source package Branch Version Maintainer Status