CVE-2019-5797: Race condition in DOMStorage
A race condition flaw was found in the DOMStorage component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=916523
External References:
https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop12.html
Other sources
Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2019-5797?
CVE-2019-5797 is classified as a moderate severity vulnerability due to its impact on heap memory corruption.
How do I fix CVE-2019-5797?
To fix CVE-2019-5797, update your Google Chrome or Chromium browser to version 73.0.3683.75 or later.
What component is affected by CVE-2019-5797?
CVE-2019-5797 affects the DOMStorage component in Google Chrome.
Can CVE-2019-5797 be exploited remotely?
Yes, CVE-2019-5797 can potentially be exploited remotely via a crafted HTML page.
What versions of Google Chrome are vulnerable to CVE-2019-5797?
Google Chrome versions prior to 73.0.3683.75 are vulnerable to CVE-2019-5797.