CVE-2019-5843 describes an out-of-bounds memory access vulnerability in Google Chrome versions prior to 74.0.3729.108, specifically within its JavaScript engine. This high-severity flaw (CVSS 8.8) could allow a remote attacker to potentially exploit heap corruption and achieve high impact on confidentiality, integrity, and availability by enticing a user to visit a specially crafted HTML page. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the vulnerability's nature suggests a significant risk if exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 74.0.3729.108CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.