CVE-2019-5796 describes a data race vulnerability in the extensions guest view component of Google Chrome prior to version 73.0.3683.75, impacting various Google and openSUSE products. This high-severity flaw (CVSS 7.5) could allow a remote attacker to achieve heap corruption through a crafted HTML page, leading to high impacts on confidentiality, integrity, and availability. While not currently on CISA's KEV catalog, an ExploitDB entry (EDB-46566) exists, and the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 73.0.3683.75CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:a:opensuse:backports_sle:15.0:-:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* | ||
42.3CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.