CVE-2019-5786: Google Chrome Blink Use-After-Free Vulnerability

Medium severity, CVSS 6.5. Actively exploited: in CISA KEV since 2022-05-23. EPSS: 61.1% chance of exploitation in the next 30 days.

Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

Affected products

  • Google Chrome: before 72.0.3626.121 (fixed in 72.0.3626.121)

Published 2019-06-27. Last modified 2026-06-17.