Google plugs Chrome zero-day exploited in the wild
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-5786 | Actively Exploited Use-After-Free in Google Chrome Blink CVE-2019-5786 is a use-after-free (object lifetime) flaw in Blink, the rendering engine of Google Chrome, fixed in Chrome 72.0.3626.121. A remote attacker triggers it by luring a user to a crafted HTML page, where the stale object allows an out-of-bounds memory access within the renderer process. Successful exploitation produces memory corruption in the browser renderer — scored in the CVSS vector primarily as high availability impact — and Google disclosed the flaw being actively exploited in targeted attacks, reportedly chained with a separate Windows zero-day that Microsoft patched out of band in March 2019. Anyone running Chrome older than 72.0.3626.121 was affected, which at disclosure time meant a large share of Chrome's billion-plus desktop user base. Exploitation is confirmed in the wild: the issue was a zero-day before the patch, it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-23, and EPSS assigns a ~61.5% probability of exploitation within 30 days (99th percentile). Do: Update Chrome to 72.0.3626.121 or later — verify via the browser's About/Settings help page and relaunch any pending auto-update, since Chrome self-updates but requires a relaunch. Treat as a KEV priority and patch per vendor instructions, and apply Microsoft's March 2019 updates, including the out-of-band Windows fix, because the Chrome flaw was used in combination with a Windows zero-day in the observed targeted attacks. | 6.5 | 62% | KEV PoC |
| mass≈1 billion+ Chrome users/installations at the time (all Chrome deployments on versions before 72.0.3626.121) |
Full article202 words · extracted from helpnetsecurity.com · click to collapse
If you’re using Google’s Chrome browser and have not yet upgraded to the latest available version, do so now or risk being hit by attackers.

About CVE-2019-5786
Google is warning users about a (now patched) zero-day vulnerability for which an exploit “exists in the wild.”
They didn’t come right out and say that the exploit is being actively used by attackers, but judging by the barrage of calls by Google’ security employees and bosses to users to update their browsers, it sure seems like it might be, and widely.
Google hasn’t revealed much about CVE-2019-5786: we known that it affects the browser’s FileReader API, that it’s a use-after-free vulnerability, and that it can allow attackers to escape the Chrome sandbox and perform remote code execution on the underlying operating system.
We also know that it was reported by Clement Lecigne of Google’s Threat Analysis Group a week ago (on February 27).
Update ASAP!
A fix for the flaw has been shipped with the latest desktop (Windows, Mac, Linux) and Android Chrome versions, as well as that for Chrome OS.
If they haven’t already, desktop Chrome users are urged to upgrade to v72.0.3626.121, Android users to v72.0.3626.121, and Chrome OS users to v72.0.3626.122.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2019/03/06/chrome-cve-2019-5786/