Learn about CVE-2019-5767 affecting Google Chrome on Android. Discover the impact, technical details, affected versions, and mitigation steps for this security vulnerability.
CVE-2019-5767 was published on February 19, 2019, and affects Google Chrome on Android versions prior to 72.0.3626.81. The vulnerability allowed malicious applications to exploit the permission user interface (UI) in WebAPKs, potentially compromising sensitive privacy and security data.
Understanding CVE-2019-5767
This CVE entry pertains to a security vulnerability in Google Chrome on Android that could be exploited by convincing users to install a specially crafted APK file.
What is CVE-2019-5767?
Prior to version 72.0.3626.81 of Google Chrome on Android, the permission user interface (UI) in WebAPKs did not provide sufficient protection. This flaw enabled attackers to manipulate the UI and access web APIs handling sensitive data.
The Impact of CVE-2019-5767
The vulnerability allowed malicious applications to exploit the UI, potentially gaining unauthorized access to sensitive privacy and security data. Successful exploitation required user interaction to install a specially designed APK file.
Technical Details of CVE-2019-5767
Google Chrome on Android versions prior to 72.0.3626.81 is susceptible to the following:
Vulnerability Description
Insufficient protection of permission UI in WebAPKs allowed attackers to access sensitive web APIs via a crafted APK.
Affected Systems and Versions
Exploitation Mechanism
To exploit this vulnerability, an attacker needed to convince the user to install a specially designed APK file.
Mitigation and Prevention
It is crucial to take immediate steps to address and prevent CVE-2019-5767:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates