KLA11588
Multiple vulnerabilities in Google Chrome

Обновлено: 03/06/2020
Дата обнаружения
22/10/2019
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Google Chrome. Malicious users can exploit these vulnerabilities to execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. Use-after-free vulnerability in media can be exploited to arbitrary code execution;
  2. Buffer overrun vulnerability in Blink can be exploited to arbitrary code execution;
  3. URL spoof vulnerability in navigation can be exploited to arbitrary code execution;
  4. Privilege elevation vulnerability in Installer can be exploited to arbitrary code execution;
  5. URL bar spoofing vulnerability can be exploited to arbitrary code execution;
  6. CSP bypass vulnerability can be exploited to arbitrary code execution;
  7. Extension permission bypass vulnerability can be exploited to arbitrary code execution;
  8. Out-of-bounds read vulnerability in PDFium can be exploited to arbitrary code execution;
  9. File storage disclosure vulnerability can be exploited to arbitrary code execution;
  10. HTTP authentication spoof vulnerability can be exploited to arbitrary code execution;
  11. File download protection bypass vulnerability can be exploited to arbitrary code execution;
  12. Cross-context information leak vulnerability can be exploited to arbitrary code execution;
  13. Buffer overflow vulnerability in expat can be exploited to arbitrary code execution;
  14. Cross-origin data leak vulnerability can be exploited to arbitrary code execution;
  15. CSS injection vulnerability can be exploited to arbitrary code execution;
  16. Address bar spoofing vulnerability can be exploited to arbitrary code execution;
  17. Service worker state error vulnerability can be exploited to arbitrary code execution;
  18. IDN spoof vulnerability can be exploited to arbitrary code execution;
Пораженные продукты

Google Chrome earlier than 78.0.3904.70

Решение

Update to the latest version
Google Chrome download page

Первичный источник обнаружения
Stable Channel Update for Desktop
Оказываемое влияние
?
ACE 
[?]

DoS 
[?]

SUI 
[?]
Связанные продукты
Google Chrome
CVE-IDS
CVE-2019-136996.8High
CVE-2019-137006.8High
CVE-2019-137014.3Warning
CVE-2019-137026.8High
CVE-2019-137034.3Warning
CVE-2019-137044.3Warning
CVE-2019-137054.3Warning
CVE-2019-137066.8High
CVE-2019-137074.3Warning
CVE-2019-137084.3Warning
CVE-2019-137094.3Warning
CVE-2019-137104.3Warning
CVE-2019-137115.0Critical
CVE-2019-159035.0Critical
CVE-2019-137134.3Warning
CVE-2019-137144.3Warning
CVE-2019-137154.3Warning
CVE-2019-137164.3Warning
CVE-2019-137174.3Warning
CVE-2019-137184.3Warning
CVE-2019-137194.3Warning
CVE-2019-137654.3Warning
Узнай статистику распространения уязвимостей в твоем регионе