CVE-2019-5774: Debian Linux

High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.

Omission of the .desktop filetype from the Safe Browsing checklist in SafeBrowsing in Google Chrome on Linux prior to 72.0.3626.81 allowed an attacker who convinced a user to download a .desktop file to execute arbitrary code via a downloaded .desktop file.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Fedoraproject Fedora: version 29 only; version 30 only
  • Google Chrome: before 72.0.3626.81 (fixed in 72.0.3626.81)
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only

Published 2019-02-19. Last modified 2026-06-17.