PT-2019-2786 · Google+3 · Google Chrome+3
Mark Amery
·
Publicado
2019-07-15
·
Atualizado
2024-06-15
·
CVE-2019-5848
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 75.0.3770.142
Description
The issue concerns incorrect font handling in autofill, allowing a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This could also lead to unauthorized access to protected information or cause a denial of service with a specially formed web page.
Recommendations
For versions prior to 75.0.3770.142, update to version 75.0.3770.142 or later to resolve the issue.
Correção
Information Disclosure
Cleartext Storage of Sensitive Information
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Google Chrome
Red Hat
Suse