CERT-In Vulnerability Note
CIVN-2019-0185
Multiple vulnerabilities in Google Chrome
Original Issue Date:November 25, 2019
Severity Rating: HIGH
Software Affected
- Google Chrome Version prior to 78.0.3904.87
Overview
Multiple vulnerabilities have been reported in Google chrome which could be exploited by remote attackers to execute arbitrary code on the targeted system.
Description
Multiple vulnerabilities exists in the Bluetooth system of Google Chrome due to boundary error and use-after-free and out-of-bound access in Bluetooth component. A remote attacker could exploit these vulnerabilities by creating a specially crafted webpage.
Successful exploitation of these vulnerabilities could allow remote attacker to execute arbitrary code in the context of the browser, obtain sensitive information, bypass security restrictions and perform unauthorized actions, or cause denial-of-service conditions on the target system.
Solution
Upgrade to Google chrome version 78.0.3904.108
https://chromereleases.googleblog.com/2019/11/stable-channel-update-for-desktop_18.html
Vendor Information
Google
https://chromereleases.googleblog.com/2019/11/stable-channel-update-for-desktop_18.html
References
Google
https://chromereleases.googleblog.com/2019/11/stable-channel-update-for-desktop_18.html
Center for Internet Security
https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2019-124/
CVE Name
CVE-2019-13723
CVE-2019-13724
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|