PT-2019-2786 · Google+3 · Google Chrome+3
Mark Amery
·
Published
2019-07-15
·
Updated
2024-06-15
·
CVE-2019-5848
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 75.0.3770.142
Description
The issue concerns incorrect font handling in autofill, allowing a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This could also lead to unauthorized access to protected information or cause a denial of service with a specially formed web page.
Recommendations
For versions prior to 75.0.3770.142, update to version 75.0.3770.142 or later to resolve the issue.
Fix
Information Disclosure
Cleartext Storage of Sensitive Information
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Google Chrome
Red Hat
Suse