Description
Multiple vulnerabilities were found in Google Chrome. Malicious users can exploit these vulnerabilities to execute arbitrary code, obtain sensitive information, bypass security restrictions, cause denial of service.
Below is a complete list of vulnerabilities:
- Use-after-free vulnerability in ServiceWorker can be exploited remotely via specially designed website to execute arbitrary code
- Incorrectly credentialed requests in CORS can be exploited remotely to obtain sensitive information
- Incorrect map processing in V8 core can be exploited remotely via specially designed website to bypass security restrictions
- Incorrect CORS handling in XHR can be exploited remotely via specially designed website to cause denial of service
- Inconsistent security UI placement in Google Chrome can be exploited remotely to obtain sensitive information
- URL spoofing in Omnibox on iOS can be exploited remotely to obtain sensitive information
- Out of bounds reading in Swiftshader can be exploited remotely via specially designed website to cause denial of service
- Heap buffer overflow in Angle can be exploited remotely via specially designed website to cause denial of service
- Cross-origin resources size disclosure in Appcache of Google Chrome can be exploited remotely to obtain sensitive information
- Overly permissive tab access in Extensions of Google Chrome can be exploited remotely to obtain sensitive information
- Incorrect handling of certain code points in Blink can be exploited remotely via specially designed website to cause denial of service
- Popup blocker bypass vulnerability in Google Chrome can be exploited remotely via specially designed website to bypass security restrictions
- Out of bounds reading in Skia can be exploited remotely to cause denial of service
Original advisories
Related products
- Google-Chrome
- Google-Chrome-Enterprise-for-current-user
- Google-Chrome-for-KIS
- Google-Chrome-for-current-user
CVE list
- CVE-2019-5828 high
- CVE-2019-5829 high
- CVE-2019-5830 warning
- CVE-2019-5831 high
- CVE-2019-5832 warning
- CVE-2019-5833 warning
- CVE-2019-5834 warning
- CVE-2019-5835 warning
- CVE-2019-5836 high
- CVE-2019-5837 warning
- CVE-2019-5838 warning
- CVE-2019-5839 warning
- CVE-2019-5840 warning
- CVE-2019-5849 high
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!