FlawAtlas
Search the atlas
CVE-2019-5786 Moderate

Confirmed as exploited

CVE-2019-5786

Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

Exploit probability 61.5%
Published June 27, 2019
Required by June 13, 2022
Last source change March 14, 2026

01 / ACTION

Required action

Apply updates per vendor instructions.

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown
npm puppeteer

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2024:10681-1
related OPENSUSE-SU-2024:12948-1

04 / EVIDENCE

Source records

Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities CVE-2019-5786

Google Chrome Blink contains a heap use-after-free vulnerability that allows an attacker to potentially perform out of bounds memory access via a crafted HTML page.

View original source
Open Source Vulnerabilities CVE-2019-5786

Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

View original source
Open Source Vulnerabilities GHSA-c2gp-86p4-5935

Versions of `puppeteer` prior to 1.13.0 are vulnerable to the Use-After-Free vulnerability in Chromium (CVE-2019-5786). The Chromium FileReader API is vulnerable to Use-After-Free which may lead to Remote Code Execution. ## Recommendation Upgrade to version 1.13.0 or later.

View original source

05 / REFERENCES

Further evidence