KEVIntel
6.5
CVSS
Medium

CVE-2019-5786

PUBLISHED

Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access...

Exploited in the wild Remote Low complexity
Vendor
Google
Product
Chrome
Published
Jun 27, 2019
EPSS

Description

Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

cisa metasploit

CVSS scores

CVSS v3.1 6.5 Medium

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVSS v2.0 4.3

AV:N/AC:M/Au:N/C:N/I:N/A:P

Exploitation status

Exploited in the wild

Recorded 2022-05-23 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
partial

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA May 23, 2022

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

chrome_filereader_uaf

metasploit · Created Unknown

Metasploit module for CVE-2019-5786

exodusintel/CVE-2019-5786

github · Created 2019-03-20 18:43:49 UTC · 256 stars

FileReader Exploit

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Metasploit