CVE-2019-5765: Medium severity google chrome vulnerability
An exposed debugging endpoint in the browser in Google Chrome on Android prior to 72.0.3626.81 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted Intent.
Other sources
An insufficient policy enforcement flaw was found in the the browser component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=922627
External References:
https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-5765?
CVE-2019-5765 has a high severity rating due to its potential to expose sensitive information.
How do I fix CVE-2019-5765?
To fix CVE-2019-5765, update Google Chrome to version 72.0.3626.81 or later.
Which software versions are affected by CVE-2019-5765?
CVE-2019-5765 affects Google Chrome versions prior to 72.0.3626.81 and various distributions of Chromium.
Can CVE-2019-5765 be exploited remotely?
CVE-2019-5765 is not remotely exploitable; it requires local access to the device.
Is there a workaround for CVE-2019-5765?
There is no specific workaround for CVE-2019-5765, and upgrading is the recommended solution.