Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-5786

94
FAUCET Score

CVE-2019-5786 is an object lifetime issue in Blink, affecting Google Chrome versions prior to 72.0.3626.121. This vulnerability allows a remote attacker to achieve out-of-bounds memory access through a specially crafted HTML page. It carries a CVSS score of 6.5 (Medium) due to its network-based attack vector and low attack complexity, with a high potential impact on availability. This CVE is notable for being actively exploited in the wild, with a Metasploit module publicly available, and has garnered significant community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 72.0.3626.121CPE matchmatch criteria
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
61.54%
Probability of exploitation in next 30 days
EPSS Percentile
99.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Added to KEV · May 23, 2022
Metasploit: Chrome 72.0.3626.119 FileReader UaF exploit for Windows 7 x86 · Mar 21, 2019
ExploitDB: EDB-46812 · May 8, 2019
This CVE's current EPSS score of 0.6154 is in the 100th percentile among its peer group of 26,208 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

apachepatch availablevia llm_extracted
dogukanurkerpatch availablevia llm_extracted
View patch
hppatch availablevia llm_extracted
View patch
kenticopatch availablevia llm_extracted
View patch
kongpatch availablevia llm_extracted
View patch
npmpatch availablevia ghsa
Product: puppeteerFixed in: 1.13.0
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6 SupplementaryFixed in: chromium-browser-0:72.0.3626.121-1.el6_10
View patch
bentomlvendor investigatingvia llm_extracted
googlevendor investigatingvia nvd_reference
View patch

Vendor Advisories (8)

npmGHSA-c2gp-86p4-5935medium

Use-After-Free in puppeteer

Sep 2, 2020
apachellm-apache-f76939b952e6cd8cHIGH

Niagara Chromium Vulnerability

May 9, 2019
hpllm-hp-2529d9b3f64b3510HIGH

Niagara Chromium Vulnerability

May 9, 2019
dogukanurkerllm-dogukanurker-6f8cbd3a11c4e8a2HIGH

Niagara Chromium Vulnerability

May 9, 2019
kenticollm-kentico-ca6ec6320420c462HIGH

Niagara Chromium Vulnerability

May 9, 2019
kongllm-kong-82d9aaea7c5532eeHIGH

Niagara Chromium Vulnerability

May 9, 2019
bentomlllm-bentoml-69b55dc8e2c71adcHIGH

Niagara Chromium Vulnerability

May 9, 2019
redhatCVE-2019-5786Important

chromium-browser: Use-after-free in FileReader

Mar 1, 2019

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
chromereleases.googleblog.com / 2019/03/stable-channel-update-for-desktop.html
Release NotesVendor Advisory
crbug.com / 936448
ExploitIssue Tracking