EXPOSURES › CVE-2019-5786
CVE-2019-5786
HIGH ⌖ ON CISA KEV · EXPLOITEDA use-after-free vulnerability in Chrome Blink allowed out-of-bounds memory access via a crafted HTML page and was actively exploited in the wild.
This use-after-free flaw in Google Chrome's Blink engine enabled attackers to execute arbitrary code by leveraging out-of-bounds memory access through malicious web pages. DIB organizations must ensure Chrome is patched to the latest version to prevent exploitation, as this vulnerability was actively exploited in the wild and represents a significant compliance risk under NIST 800-171 for unpatched software.
Shame score — The vulnerability was actively exploited in the wild and allowed remote code execution, representing a severe, avoidable failure in patch management and software supply chain security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chrome Blink contains a heap use-after-free vulnerability that allows an attacker to potentially perform out of bounds memory access via a crafted HTML page.
| PRODUCT | STATUS |
|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) Google |
Authorized |
| Google Workspace Google |
Authorized |