CVE-2019-5866: Google Chrome

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Out of bounds memory access in JavaScript in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Affected products

  • Google Chrome: before 75.0.3770.142 (fixed in 75.0.3770.142)

Published 2019-11-25. Last modified 2026-06-17.