CVE-2019-5862 describes an insufficient data validation vulnerability in Google Chrome's AppCache, affecting versions prior to 76.0.3809.87. This medium-severity vulnerability (CVSS 6.5) could allow a remote attacker, after compromising the renderer process, to bypass site isolation through a crafted HTML page, leading to high integrity impact. There is no evidence of active exploitation, nor are public exploit codes available, though it has garnered some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 76.0.3809.87CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.