Description: | Summary: Google Chrome is prone to multiple vulnerabilities.
Vulnerability Insight: Multiple flaws are due to:
- Multiple out of bounds write errors in V8 and Mojo.
- A missing check for JS-simulated input events in Blink.
- A missing origin check related to HLS manifests in Blink.
- Multiple out of bounds read errors in Blink, WebAudio, SwiftShader, Little-CMS, PDFium and WebRTC.
- An integer overflow error in Skia.
- Multiple use after free errors in WebRTC and Memory Instrumentation.
- An user confirmation bypass error in external protocol handling.
- A stack buffer overflow error in SwiftShader.
- An improper file access control in DevTools and Blink.
- Multiple url spoofing errors.
- The content security policy bypass error in Blink.
- A security bypass error in Autofill.
- An insufficient policy enforcement in extensions API in Google Chrome.
Vulnerability Impact: Successful exploitation will allow remote attackers to bypass security restrictions, cause denial of service condition, disclose sensitive information and conduct spoofing attack.
Affected Software/OS: Google Chrome version prior to 69.0.3497.81 on Windows
Solution: Upgrade to Google Chrome version 69.0.3497.81 or later. Please see the references for more information.
CVSS Score: 6.8
CVSS Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
|