CVE-2019-5816Improper Control of a Resource Through its Lifetime in Google Chrome

Severity
8.8HIGHNVD
EPSS
0.6%
top 30.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 27
Latest updateMay 24

Description

Process lifetime issue in Chrome in Google Chrome on Android prior to 74.0.3729.108 allowed a remote attacker to potentially persist an exploited process via a crafted HTML page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

CVEListV5google/chromeunspecified74.0.3729.108
NVDgoogle/chrome< 74.0.3729.108
NVDopensuse/leap15.0, 15.1, 42.3+2
NVDopensuse/backportssle-15

Also affects: Fedora 29

🔴Vulnerability Details

3
GHSA
GHSA-43g9-qgw6-3pfp: Process lifetime issue in Chrome in Google Chrome on Android prior to 742022-05-24
OSV
CVE-2019-5816: Process lifetime issue in Chrome in Google Chrome on Android prior to 742019-06-27
CVEList
CVE-2019-5816: Process lifetime issue in Chrome in Google Chrome on Android prior to 742019-06-27

📋Vendor Advisories

2
Red Hat
chromium-browser: Exploit persistence extension on Android2019-04-23
Debian
CVE-2019-5816: chromium - Process lifetime issue in Chrome in Google Chrome on Android prior to 74.0.3729....2019

💬Community

1
Bugzilla
CVE-2019-5816 chromium-browser: Exploit persistence extension on Android2019-04-25
CVE-2019-5816 — Google Chrome vulnerability | cvebase