CVE-2019-5816 describes a process lifetime issue in Google Chrome on Android, specifically versions prior to 74.0.3729.108, which allowed a remote attacker to potentially persist an exploited process through a crafted HTML page. This vulnerability carries a high CVSS score of 8.8, indicating a critical severity due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While the vulnerability has garnered some media coverage and community discussion, there is currently no evidence of active exploitation, nor is public exploit code available in common repositories like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 74.0.3729.108CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
29CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:* | ||
sle-15CPE matchmatch criteria | cpe:2.3:o:opensuse:backports:sle-15:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.