CVE-2019-5848

Description

Incorrect font handling in autofill in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.181

Associated Vulnerability

VulnerabilityOS Platform
Update Google Chrome (75.0.3770.142) fixes CVE-2019-5847 and CVE-2019-5848Windows
Update Google Chrome (x64) (75.0.3770.142) fixes CVE-2019-5847 and CVE-2019-5848Windows
Vulnerabilities CVE-2019-5847,CVE-2019-5848 are fixed in Update for Google Chrome For Mac (75.0.3770.142)Mac
chromium security update(DSA-4500-1) chromium_76.0.3809.100-1~deb10u1_amd64.debLinux
Update Google Chrome (75.0.3770.142) fixes CVE-2019-5847 and CVE-2019-5848 (For Debian)Linux
Update Google Chrome (75.0.3770.142) fixes CVE-2019-5847 and CVE-2019-5848 (For Centos)Linux
Update Google Chrome (75.0.3770.142) fixes CVE-2019-5847 and CVE-2019-5848 (For RedHat)Linux
Update Google Chrome (75.0.3770.142) fixes CVE-2019-5847 and CVE-2019-5848 (For Suse)Linux
Update Google Chrome (75.0.3770.142) fixes CVE-2019-5847 and CVE-2019-5848 (For Ubuntu)Linux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-310361Google Chrome (75.0.3770.142)
PATCH-310362Google Chrome (x64) (75.0.3770.142)
PATCH-609673Google Chrome for Mac (132.0.6834.83, 132.0.6834.84)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234