CVE-2019-5786: Use After Free
(updated )
Object lifetime issue in Blink in Google Chrome allowed a remote attacker to potentially perform out-of-bounds memory access via a crafted HTML page.
References
- blog.exodusintel.com/2019/03/20/cve-2019-5786-analysis-and-exploitation/
- chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop.html
- crbug.com/936448
- github.com/GoogleChrome/puppeteer/issues/4141
- github.com/advisories/GHSA-c2gp-86p4-5935
- nvd.nist.gov/vuln/detail/CVE-2019-5786
- snyk.io/vuln/SNYK-JS-PUPPETEER-174321
- www.npmjs.com/advisories/824
Detect and mitigate CVE-2019-5786 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →