Home > Cyber News > CVE-2019-5786: Vulnerability in Google Chrome, Patch Immediately
CYBER NEWS

CVE-2019-5786: Vulnerability in Google Chrome, Patch Immediately

Google Chrome has been found vulnerable to a zero-day vulnerability for which there may be an active exploit in the wild. The vulnerability in question is assigned the CVE-2019-5786 number, and fortunately, it has been patched.




All Chrome users are urged to update to the latest version of the browser to avoid attacks.

The vulnerability in question is assigned the CVE-2019-5786 number, and fortunately, it has been patched. All Chrome users are urged to update to the latest version of the browser to avoid attacks.

CVE-2019-5786 Technical Information

Google has not said much about the zero-day. “Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed,” the company said in an announcement.

Related: [wplinkpreview url=”https://sensorstechforum.com/google-chrome-mitigates-spectre-vulnerability-via-site-isolation/”]Google Chrome Mitigates Spectre Vulnerability Via Site Isolation

What is known about the vulnerability is that it affects the browser\s FileReader API. It is a use-after-free flaw that can allow attackers to escape the Chrome sandbox and carry out remote code execution attacks on vulnerable systems.

CVE-2019-5786 was reported by Clement Lecigne who is a researcher for Google Threat Analysis Group on February 27. The good news is that the vulnerability has been fixed in the latest desktop versions of Chrome as well as in the Android and Chrome OS systems.

That being said, desktop Chrome users should immediately upgrade to v72.0.3626.121, Android users to v72.0.3626.121, and Chrome OS users to v72.0.3626.122.

Milena Dimitrova

An inspired writer and content manager who has been with SensorsTechForum since the project started. A professional with 10+ years of experience in creating engaging content. Focused on user privacy and malware development, she strongly believes in a world where cybersecurity plays a central role. If common sense makes no sense, she will be there to take notes. Those notes may later turn into articles! Follow Milena @Milenyim

More Posts

Follow Me:
Twitter

Leave a Comment

Your email address will not be published. Required fields are marked *

This website uses cookies to improve user experience. By using our website you consent to all cookies in accordance with our Privacy Policy.
I Agree