Google Chrome prior 74.0.3729.108 on MacOS Developer Tools String privilege escalation – Digitalmunition

Exploit/Advisories Cybersecurity study of the dark web exposes vulnerability to machine identities -- ScienceDaily

Published on June 28th, 2019 📆 | 5750 Views ⚑


Google Chrome prior 74.0.3729.108 on MacOS Developer Tools String privilege escalation

CVSS Meta Temp ScoreCurrent Exploit Price (≈)

A vulnerability was found in Google Chrome on MacOS (Web Browser) and classified as critical. This issue affects some unknown processing of the component Developer Tools. The manipulation as part of a String leads to a privilege escalation vulnerability. Using CWE to declare the problem leads to CWE-269. Impacted is confidentiality, integrity, and availability.

The bug was discovered 04/23/2019. The weakness was presented 06/27/2019. The identification of this vulnerability is CVE-2019-5819 since 01/09/2019. Attacking locally is a requirement. A single authentication is necessary for exploitation. The technical details are unknown and an exploit is not publicly available. The pricing for an exploit might be around USD $5k-$25k at the moment (estimation calculated on 06/27/2019). It is expected to see the exploit prices for this product increasing in the near future.

The vulnerability was handled as a non-public zero-day exploit for at least 65 days. During that time the estimated underground price was around $25k-$100k.

Upgrading to version 74.0.3729.108 eliminates this vulnerability.

See 137007, 137006, 137005 and 137004 for similar entries.




VulDB Meta Base Score: 5.3
VulDB Meta Temp Score: 5.1

VulDB Base Score: 5.3
VulDB Temp Score: 5.1
VulDB Vector: 🔒
VulDB Reliability: 🔍


VulDB Base Score: 🔒
VulDB Temp Score: 🔒
VulDB Reliability: 🔍
Class: Privilege escalation (CWE-269)
Local: Yes
Remote: No

Availability: 🔒
Status: Not defined

Price Prediction: 🔍
Current Price Estimation: 🔒

Threat Intelligenceinfoedit

Threat: 🔍
Adversaries: 🔍
Geopolitics: 🔍
Economy: 🔍
Predictions: 🔍
Remediation: 🔍Recommended: Upgrade
Status: 🔍

0-Day Time: 🔒

Upgrade: Chrome 74.0.3729.108

01/09/2019 CVE assigned
04/23/2019 +104 days Vulnerability found
06/27/2019 +65 days Advisory disclosed
06/27/2019 +0 days VulDB entry created
06/27/2019 +0 days VulDB last updateVendor:
CVE: CVE-2019-5819 (🔒)
OSVDB: – Google Chrome developer tools security bypass

See also: 🔒

Created: 06/27/2019 10:13 PM
Complete: 🔍


No comments yet. Please log in to comment.

Check our Alexa App!

Tagged with:

Leave a Reply

Your email address will not be published. Required fields are marked *