Learn about CVE-2019-5864 where Google Chrome before 76.0.3809.87 had a CORS vulnerability allowing attackers to bypass content security policies via malicious extensions. Find mitigation steps here.
Google Chrome before version 76.0.3809.87 had a vulnerability in the CORS feature that allowed attackers to bypass content security policies via malicious extensions.
Understanding CVE-2019-5864
Before version 76.0.3809.87, a lack of data validation in CORS in Google Chrome enabled attackers to exploit the browser's security.
What is CVE-2019-5864?
The Impact of CVE-2019-5864
Technical Details of CVE-2019-5864
Google Chrome's vulnerability in the CORS feature had the following technical details:
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
To address CVE-2019-5864, consider the following steps:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates