CVE-2019-13763: Medium severity google chrome vulnerability
An insufficient policy enforcement flaw was found in the payments component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=101160
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Other sources
Insufficient policy enforcement in payments in Google Chrome prior to 79.0.3945.79 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-13763?
CVE-2019-13763 is a vulnerability in Google Chrome that allows a remote attacker to leak cross-origin data.
How can the vulnerability in CVE-2019-13763 be exploited?
The vulnerability in CVE-2019-13763 can be exploited by a remote attacker who has already compromised the renderer process.
What is the severity of CVE-2019-13763?
CVE-2019-13763 has a severity rating of medium.
Which versions of Google Chrome are affected by CVE-2019-13763?
Google Chrome versions prior to 79.0.3945.79 are affected by CVE-2019-13763.
How can I fix the vulnerability in CVE-2019-13763?
To fix the vulnerability in CVE-2019-13763, update Google Chrome to version 79.0.3945.79 or later.