CVE-2019-5817 describes a heap buffer overflow vulnerability in ANGLE, a component of Google Chrome on Windows prior to version 74.0.3729.108, also affecting Debian, Fedora, Microsoft, and OpenSUSE. This high-severity flaw (CVSS 8.8) could allow a remote attacker to achieve heap corruption and potentially execute arbitrary code by enticing a user to visit a specially crafted HTML page. While no public exploit code or active exploitation has been observed, and it is not on CISA's KEV catalog, its high potential impact warrants attention. Community discussion and media coverage indicate some awareness of this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 74.0.3729.108CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
29CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:* | ||
sle-15CPE matchmatch criteria | cpe:2.3:o:opensuse:backports:sle-15:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.