CVE-2019-5789: Use after free in WebMIDI
An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.
Other sources
An use after free flaw was found in the WebMIDI component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=921581
External References:
https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop12.html
— Red Hat
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2019-5789?
CVE-2019-5789 is classified as high severity due to its potential to allow remote code execution.
How do I fix CVE-2019-5789?
To fix CVE-2019-5789, upgrade Google Chrome or Chromium browser to version 73.0.3683.75 or later.
What causes CVE-2019-5789?
CVE-2019-5789 is caused by an integer overflow leading to a use-after-free vulnerability in the WebMIDI component of Google Chrome.
Which versions of Chrome are affected by CVE-2019-5789?
CVE-2019-5789 affects Google Chrome versions prior to 73.0.3683.75.
Can CVE-2019-5789 be exploited remotely?
Yes, CVE-2019-5789 can be exploited remotely via a specially crafted HTML page.