CVE-2019-0746: Microsoft ChakraCore

Medium severity, CVSS 6.5. EPSS: 6.6% chance of exploitation in the next 30 days.

An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge, aka 'Scripting Engine Information Disclosure Vulnerability'.

Affected products

  • Microsoft ChakraCore: affected versions not specified
  • Microsoft Edge: affected versions not specified
  • Microsoft Internet Explorer: version 10 only; version 11 only; version 9 only

Published 2019-04-09. Last modified 2026-06-17.