⚠ Actively exploited
Added to CISA KEV on 2022-05-23. Federal agencies required to patch by 2022-06-13. Required action: Apply updates per vendor instructions..

CVE-2019-5786Use After Free in Google Chrome

CWE-416Use After Free22 documents15 sources
Severity
6.5MEDIUMNVD
EPSS
89.4%
top 0.45%
CISA KEV
KEV
Added 2022-05-23
Due 2022-06-13
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJun 27
KEV addedMay 23
KEV dueJun 13
CISA Required Action: Apply updates per vendor instructions.

Description

Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5google/chromeunspecified72.0.3626.121
NVDgoogle/chrome< 72.0.3626.121
debiandebian/chromium< chromium 72.0.3626.121-1 (bookworm)
Debianchromium/chromium< 72.0.3626.121-1+3

🔴Vulnerability Details

5
OSV
Use-After-Free in puppeteer2020-09-02
GHSA
Use-After-Free in puppeteer2020-09-02
Project0
Detection Deficit: A Year in Review of 0-days Used In-The-Wild in 2019 - Project Zero2020-07-01
OSV
CVE-2019-5786: Object lifetime issue in Blink in Google Chrome prior to 722019-06-27
VulnCheck
Google Chrome Blink Use-After-Free Vulnerability2019

💥Exploits & PoCs

2
Exploit-DB
Google Chrome 72.0.3626.119 - 'FileReader' Use-After-Free (Metasploit)2019-05-08
Metasploit
Chrome 72.0.3626.119 FileReader UaF exploit for Windows 7 x86

📋Vendor Advisories

3
CISA
Google Chrome Blink Use-After-Free Vulnerability2022-05-23
Red Hat
chromium-browser: Use-after-free in FileReader2019-03-01
Debian
CVE-2019-5786: chromium - Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a...2019

🕵️Threat Intelligence

7
Tenable
CVE-2020-6418: Google Chrome Type Confusion Vulnerability Exploited in the Wild2020-02-24
Tenable
CVE-2020-0674: Internet Explorer Remote Code Execution Vulnerability Exploited in the Wild2020-01-20
Tenable
CVE-2019-1367: Critical Internet Explorer Memory Corruption Vulnerability Exploited In The Wild2019-09-23
Securelist
IT threat evolution Q1 2019. Statistics2019-05-23
Krebs
Patch Tuesday, March 2019 Edition2019-03-13

📄Research Papers

1
arXiv
Robust Machine Learning for Encrypted Traffic Classification2020-07-20

💬Community

3
Bugzilla
CVE-2019-5786 chromium: chromium-browser: Use-after-free in FileReader [fedora-all]2019-03-04
Bugzilla
CVE-2019-5786 chromium-browser: Use-after-free in FileReader2019-03-04
Bugzilla
CVE-2019-5786 chromium: chromium-browser: Use-after-free in FileReader [epel-7]2019-03-04