New vulnerabilities in the SQLite database engine affect a wide range of applications that utilize it as a component within their software packages. Tencent Blade Team has disclosed another batch of SQLite vulnerabilities called Magellan 2.0.0. This vulnerability affects all programs that utilize the database management system that allows external queries. Using these vulnerabilities, Tencent was able to remotely execute commands in Google Chrome as long as WebSQL was enabled in the browser. This is a critical vulnerability as it means remote attackers could potentially use this vulnerability to fully compromise a computer.
Source: https://www.bleepingcomputer.com/news/security/new-magellan-20-sqlite-vulnerabilities-affect-many-programs/

