browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an erase() call, which causes the erase operation to access data that that erase operation will destroy.
2019-10-25T15:15:11.857
2024-11-21T02:53:49.897
Modified
CVSSv3.1: 9.1 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | chrome | < 54.0.2840.98 | Yes | |
Operating System | apple | macos | - | No |
Application | chrome | < 54.0.2840.99 | Yes | |
Operating System | microsoft | windows | - | No |
Application | chrome | < 54.0.2840.100 | Yes | |
Operating System | linux | linux_kernel | - | No |