Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jnghwan Kang

#29510of 53,633
8.8Total CVSS
Vulnerabilities · 1
PT-2019-1699
8.8
2019-01-30
Google · Google Chrome · CVE-2019-5774
**Name of the Vulnerable Software and Affected Versions** Google Chrome versions prior to 72.0.3626.81 **Description** The issue is related to the omission of the .desktop filetype from the Safe Browsing checklist in Google Chrome on Linux. This allowed an attacker, who convinced a user to download a .desktop file, to execute arbitrary code via the downloaded file. The exploitation of this issue may enable a remote attacker to load a .desktop file for executing arbitrary code. **Recommendations** For versions prior to 72.0.3626.81, update to version 72.0.3626.81 or later to resolve the issue. As a temporary workaround, consider avoiding the download of .desktop files from untrusted sources until the update is applied. Restrict access to the SafeBrowsing feature in Google Chrome on Linux to minimize the risk of exploitation.