PT-2019-2888 · Google+8 · Google Chrome+8
Mlfbrown
·
Published
2019-04-12
·
Updated
2024-06-15
·
CVE-2019-5827
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 74.0.3729.131
Description
The issue is related to an integer overflow in SQLite via WebSQL, which can be exploited by a remote attacker using a specially crafted HTML page. This could potentially lead to heap corruption, affecting the confidentiality, integrity, and availability of protected information.
Recommendations
For versions prior to 74.0.3729.131, update to version 74.0.3729.131 or later to resolve the issue. As a temporary workaround, consider restricting access to WebSQL in Google Chrome until the update is applied.
Exploit
Fix
Memory Corruption
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Google Chrome
Red Hat
Rocky Linux
Sqlite
Suse
Ubuntu