Medium severity6.1NVD Advisory· Published Jan 13, 2020· Updated Jun 17, 2026
CVE-2019-18893
CVE-2019-18893
Description
XSS in the Video Downloader component before 1.5 of Avast Secure Browser 77.1.1831.91 and AVG Secure Browser 77.0.1790.77 allows websites to execute their code in the context of this component. While Video Downloader is technically a browser extension, it is granted a very wide set of privileges and can for example access cookies and browsing history, spy on the user while they are surfing the web, and alter their surfing experience in almost arbitrary ways.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7<77.1.1831.91+ 1 more
- (no CPE)range: <77.1.1831.91
- cpe:2.3:a:avast:secure_browser:77.1.1831.91:*:*:*:*:*:*:*
<77.0.1790.77+ 1 more
- (no CPE)range: <77.0.1790.77
- cpe:2.3:a:avg:secure_browser:77.0.1790.77:*:*:*:*:*:*:*
- Range: <1.5
- Avast/Secure Browserdescription
- cpe:2.3:a:video_downloader_project:video_downloader:*:*:*:*:*:*:*:*Range: <1.5
Patches
Vulnerability mechanics
References
1- palant.de/2020/01/13/pwning-avast-secure-browser-for-fun-and-profit/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.