CVE-2019-5786 is an object lifetime issue in Blink, affecting Google Chrome versions prior to 72.0.3626.121. This vulnerability allows a remote attacker to achieve out-of-bounds memory access through a specially crafted HTML page. It carries a CVSS score of 6.5 (Medium) due to its network-based attack vector and low attack complexity, with a high potential impact on availability. This CVE is notable for being actively exploited in the wild, with a Metasploit module publicly available, and has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 72.0.3626.121CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Use-After-Free in puppeteer
Sep 2, 2020Niagara Chromium Vulnerability
May 9, 2019Niagara Chromium Vulnerability
May 9, 2019Niagara Chromium Vulnerability
May 9, 2019Niagara Chromium Vulnerability
May 9, 2019Niagara Chromium Vulnerability
May 9, 2019Niagara Chromium Vulnerability
May 9, 2019chromium-browser: Use-after-free in FileReader
Mar 1, 2019