Google Chrome < 72.0.3626.81 Multiple Vulnerabilities

critical Nessus Plugin ID 121514

Synopsis

A web browser installed on the remote Windows host is affected by multiple vulnerabilities.

Description

The version of Google Chrome installed on the remote Windows host is prior to 72.0.3626.81. It is, therefore, affected by multiple vulnerabilities as referenced in the 2019_01_stable-channel-update-for-desktop advisory.

- Missing URI encoding of untrusted input in DevTools in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform a Dangling Markup Injection attack via a crafted HTML page. (CVE-2019-5783)

- Incorrect lifetime handling in HTML select elements in Google Chrome on Android and Mac prior to 72.0.3626.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
(CVE-2019-5759)

- Implementation error in QUIC Networking in Google Chrome prior to 72.0.3626.81 allowed an attacker running or able to cause use of a proxy server to obtain cleartext of transport encryption via malicious network proxy. (CVE-2019-5754)

- Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (CVE-2019-5782)

- Incorrect handling of negative zero in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (CVE-2019-5755)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Google Chrome version 72.0.3626.81 or later.

See Also

http://www.nessus.org/u?6d3dace5

https://crbug.com/733943

https://crbug.com/805557

https://crbug.com/837936

https://crbug.com/849421

https://crbug.com/863663

https://crbug.com/891697

https://crbug.com/895081

https://crbug.com/895152

https://crbug.com/896722

https://crbug.com/896725

https://crbug.com/899689

https://crbug.com/900552

https://crbug.com/902427

https://crbug.com/904182

https://crbug.com/904219

https://crbug.com/904265

https://crbug.com/904714

https://crbug.com/906043

https://crbug.com/907047

https://crbug.com/908292

https://crbug.com/908749

https://crbug.com/912074

https://crbug.com/912211

https://crbug.com/913246

https://crbug.com/913296

https://crbug.com/913970

https://crbug.com/913975

https://crbug.com/914497

https://crbug.com/914731

https://crbug.com/915469

https://crbug.com/917668

https://crbug.com/918470

https://crbug.com/922627

Plugin Details

Severity: Critical

ID: 121514

File Name: google_chrome_72_0_3626_81.nasl

Version: 1.11

Type: local

Agent: windows

Family: Windows

Published: 1/31/2019

Updated: 11/24/2025

Configuration: Enable thorough checks (optional)

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.9

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2019-5783

CVSS v3

Risk Factor: Critical

Base Score: 9.6

Temporal Score: 9.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

CVSS Score Source: CVE-2019-5759

Vulnerability Information

CPE: cpe:/a:google:chrome

Required KB Items: installed_sw/Google Chrome

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 1/29/2019

Vulnerability Publication Date: 1/29/2019

Reference Information

CVE: CVE-2018-20073, CVE-2019-13684, CVE-2019-5754, CVE-2019-5755, CVE-2019-5756, CVE-2019-5757, CVE-2019-5758, CVE-2019-5759, CVE-2019-5760, CVE-2019-5761, CVE-2019-5762, CVE-2019-5763, CVE-2019-5764, CVE-2019-5765, CVE-2019-5766, CVE-2019-5767, CVE-2019-5768, CVE-2019-5769, CVE-2019-5770, CVE-2019-5771, CVE-2019-5772, CVE-2019-5773, CVE-2019-5774, CVE-2019-5775, CVE-2019-5776, CVE-2019-5777, CVE-2019-5778, CVE-2019-5779, CVE-2019-5780, CVE-2019-5781, CVE-2019-5782, CVE-2019-5783, CVE-2019-5785

BID: 106767