Kaspersky ID:
KLA11491
検出日:
06/04/2019
更新日:
01/28/2026

説明

Multiple vulnerabilities were found in Google Chrome. Malicious users can exploit these vulnerabilities to execute arbitrary code, obtain sensitive information, bypass security restrictions, cause denial of service.

Below is a complete list of vulnerabilities:

  1. Use-after-free vulnerability in ServiceWorker can be exploited remotely via specially designed website to execute arbitrary code
  2. Incorrectly credentialed requests in CORS can be exploited remotely to obtain sensitive information
  3. Incorrect map processing in V8 core can be exploited remotely via specially designed website to bypass security restrictions
  4. Incorrect CORS handling in XHR can be exploited remotely via specially designed website to cause denial of service
  5. Inconsistent security UI placement in Google Chrome can be exploited remotely to obtain sensitive information
  6. URL spoofing in Omnibox on iOS can be exploited remotely to obtain sensitive information
  7. Out of bounds reading in Swiftshader can be exploited remotely via specially designed website to cause denial of service
  8. Heap buffer overflow in Angle can be exploited remotely via specially designed website to cause denial of service
  9. Cross-origin resources size disclosure in Appcache of Google Chrome can be exploited remotely to obtain sensitive information
  10. Overly permissive tab access in Extensions of Google Chrome can be exploited remotely to obtain sensitive information
  11. Incorrect handling of certain code points in Blink can be exploited remotely via specially designed website to cause denial of service
  12. Popup blocker bypass vulnerability in Google Chrome can be exploited remotely via specially designed website to bypass security restrictions
  13. Out of bounds reading in Skia can be exploited remotely to cause denial of service

オリジナルアドバイザリー

エクスプロイテーション

Public exploits exist for this vulnerability.

関連製品

CVEリスト

  • CVE-2019-5828
    critical
  • CVE-2019-5829
    critical
  • CVE-2019-5830
    high
  • CVE-2019-5831
    critical
  • CVE-2019-5832
    high
  • CVE-2019-5833
    warning
  • CVE-2019-5834
    high
  • CVE-2019-5835
    high
  • CVE-2019-5836
    critical
  • CVE-2019-5837
    high
  • CVE-2019-5838
    warning
  • CVE-2019-5839
    warning
  • CVE-2019-5840
    warning
  • CVE-2019-5849
    critical

も参照してください

お住まいの地域に広がる脆弱性の統計をご覧ください statistics.securelist.com

この脆弱性についての記述に不正確な点がありますか? お知らせください!
Kaspersky IT Security Calculator
も参照してください
新しいカスペルスキー
あなたのデジタルライフを守る
も参照してください
Do you want to save your changes?
Your message has been sent successfully.