CVE-2019-5796: Race condition in Extensions
A race condition flaw was found in the Extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=918861
External References:
https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop12.html
Other sources
Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
— MITRE
Credit
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2019-5796?
CVE-2019-5796 has a severity rating that indicates high-risk potential for exploitation due to heap corruption.
How do I fix CVE-2019-5796?
To fix CVE-2019-5796, update to Google Chrome or Chromium browser version 73.0.3683.75 or later.
What type of vulnerability is CVE-2019-5796?
CVE-2019-5796 is a data race vulnerability in the extensions component of the Google Chrome browser.
What can be exploited through CVE-2019-5796?
CVE-2019-5796 allows remote attackers to potentially exploit heap corruption via a crafted HTML page.
Which versions are affected by CVE-2019-5796?
CVE-2019-5796 affects Google Chrome and Chromium browser versions prior to 73.0.3683.75.