RULE(RULE ID:321735)

Rule General Information
Release Date: 2019-04-22
Rule Name: Google Chrome FileReader Use After Free Vulnerability Attack (CVE-2019-5786)
Severity:
CVE ID:
CNNVD ID:
Rule Protection Details
Description: Google Chrome is a web browser. FileReader is one of the file reading plugins. The FileReader in versions prior to Google Chrome 72.0.3626.121 has a use-after-free vulnerability. An attacker could exploit the vulnerability to execute arbitrary code in the context of a browser or could result in a denial of service.
Impact: A use-after-free vulnerability can be exploited by an attacker in the vulnerable product. Successful exploit may cause some adverse consequences, such as crash of the product, execution of arbitrary code.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5786
https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-chrome-os.html
Solutions
Upgrading to version 72.0.3626.121 eliminates this vulnerability. The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop.html