CVE-2019-5782
50Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actepss 13%
from disclosure to weapon1766 days
Published on NVDFeb 19
1st PoC+1766d
VulnCheck+1809d
exploitation probability
13%top 4% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Affected products
Google · Chromepublic PoCs found — 1
vulncheckvulncheck.com/xdb/8b972f2f275bunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://access.redhat.com/errata/RHSA-2019:0309https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.htmlhttps://crbug.com/906043https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JVFHYCJGMZQUKYSIE2BXE4NLEGFGUXU5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQOP53LXXPRGD4N5OBKGQTSMFXT32LF6/https://www.debian.org/security/2019/dsa-4395http://www.securityfocus.com/bid/106767