CVE-2019-5787: Use after free in Canvas
An use after free flaw was found in the Canvas component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=913964
External References:
https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop12.html
Other sources
Use-after-garbage-collection in Blink in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
— MITRE
Credit
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2019-5787?
CVE-2019-5787 is classified as a high-severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2019-5787?
To fix CVE-2019-5787, update Google Chrome or Chromium-browser to version 73.0.3683.75 or higher.
What is the impact of CVE-2019-5787?
The impact of CVE-2019-5787 includes possible heap corruption, which could allow attackers to execute arbitrary code on the user's system.
Which versions are affected by CVE-2019-5787?
CVE-2019-5787 affects all versions of Google Chrome and Chromium-browser prior to 73.0.3683.75.
Is there a workaround for CVE-2019-5787?
Currently, the only recommended mitigation for CVE-2019-5787 is to upgrade to the latest version of the browser.