CVE-2019-5822 is a vulnerability in the Blink rendering engine in Google Chrome prior to version 74.0.3729.108. The issue stems from an inappropriate implementation that allows a remote attacker to bypass the same origin policy by enticing a user to visit a crafted HTML page. This could enable cross-origin data access or manipulation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (POC) for demonstrating browser-based vulnerabilities related to address bar spoofing and cross-origin download redirection. The structure is organized into three main directories: 1. attack_reproduction/address_bar_spoofing: Contains HTML files (frame1.html, test.html) that demonstrate how a browser's address bar can be manipulated using automatic downloads and JavaScript, potentially misleading users about the origin of a download. 2. attack_reproduction/original_bypass: Contains a Node.js Express server (index.js) and supporting HTML files to demonstrate download redirection attacks. The server listens on port 3000 and provides endpoints that redirect users to arbitrary URLs via /location.php?url=... This can be used to test how browsers handle downloads from different origins, including those protected by X-Frame-Options. 3. mitigation_ext: Contains a browser extension (manifest.json, download_alert.js) that attempts to detect and alert users when a cross-origin download is triggered within an iframe. The extension uses jQuery to monitor iframe content and alerts the user if a download link points to a different origin than the current page. 4. threat_model: Contains HTML files that model the threat scenario, providing links for same-origin and cross-origin downloads to illustrate the difference in browser behavior. The repository does not target a specific CVE or product but rather demonstrates a class of browser vulnerabilities. The main exploit capability is to show how a malicious site could trigger downloads from other origins, potentially bypassing user expectations or browser protections. The included mitigation extension provides a basic defense by alerting users to suspicious download activity.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.