CVE-2019-5769Improper Input Validation in Google Chrome

Severity
8.8HIGHNVD
EPSS
1.6%
top 18.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 19
Latest updateMay 14

Description

Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages6 packages

CVEListV5google/chromeunspecified72.0.3626.81
NVDgoogle/chrome< 72.0.3626.81
Debianchromium/chromium< 72.0.3626.81-1+3

Also affects: Debian Linux 9.0, Fedora 29, 30

🔴Vulnerability Details

3
GHSA
GHSA-6m7c-33xf-693j: Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 722022-05-14
OSV
CVE-2019-5769: Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 722019-02-19
CVEList
CVE-2019-5769: Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 722019-02-19

📋Vendor Advisories

2
Red Hat
chromium-browser: Insufficient validation of untrusted input in Blink2019-01-29
Debian
CVE-2019-5769: chromium - Incorrect handling of invalid end character position when front rendering in Bli...2019

💬Community

1
Bugzilla
CVE-2019-5769 chromium-browser: Insufficient validation of untrusted input in Blink2019-01-30
CVE-2019-5769 — Improper Input Validation in Google | cvebase