Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
Published: 2019-03-06
Google Chrome 72.0.3626.121 was released to address CVE-2019-5786. The company’s Clement Lecigne reports the vulnerability was exploited in the wild together with a Microsoft Windows privilege escalation vulnerability (CVE-2019-0808).
https://github.com/J0hnFFFF/chrome_cve
https://github.com/advisories/GHSA-c2gp-86p4-5935
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-5786
https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-0957
https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop.html