⚠ Actively exploited
Added to CISA KEV on 2022-05-23. Federal agencies required to patch by 2022-06-13. Required action: Apply updates per vendor instructions..

CVE-2019-13720Use After Free in Google Chrome

Severity
8.8HIGHNVD
EPSS
89.6%
top 0.44%
CISA KEV
KEV
Added 2022-05-23
Due 2022-06-13
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedNov 25
KEV addedMay 23
Latest updateMay 24
KEV dueJun 13
CISA Required Action: Apply updates per vendor instructions.

Description

Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages6 packages

CVEListV5google/chromeunspecified78.0.3904.87
NVDgoogle/chrome< 78.0.3904.87
debiandebian/chromium< chromium 78.0.3904.87-1 (bookworm)
Debianchromium/chromium< 78.0.3904.87-1+3

🔴Vulnerability Details

10
GHSA
GHSA-3qg6-gw2x-w9cq: Use after free in WebAudio in Google Chrome prior to 782022-05-24
Project0
The More You Know, The More You Know You Don’t Know - Project Zero2022-04-01
Project0
Root Cause Analyses for 0-day In-the-Wild Exploits - Project Zero2020-07-01
Project0
Detection Deficit: A Year in Review of 0-days Used In-The-Wild in 2019 - Project Zero2020-07-01
Project0
TFW you-get-really-excited-you-patch-diffed-a-0day-used-in-the-wild-but-then-find-out-it-is-the-wrong-vuln - Project Zero2020-04-01

💥Exploits & PoCs

1
Exploit-DB
Google Chrome 78.0.3904.70 - Remote Code Execution2022-05-11

📋Vendor Advisories

4
CISA
Google Chrome WebAudio Use-After-Free Vulnerability2022-05-23
Chrome
Stable Channel Update for Desktop: CVE-2019-137212019-10-31
Red Hat
chromium-browser: use-after-free in audio2019-10-29
Debian
CVE-2019-13720: chromium - Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remo...2019

🕵️Threat Intelligence

10
Tenable
CVE-2020-15999, CVE-2020-17087: Google Chrome FreeType and Microsoft Windows Kernel Zero Days Exploited in the Wild2020-11-02
Securelist
The zero-day exploits of Operation WizardOpium2020-05-28
Securelist
The zero-day exploits of Operation WizardOpium2020-05-28
Krebs
Patch Tuesday, November 2019 Edition2019-11-12
Krebs
Patch Tuesday, November 2019 Edition2019-11-12

💬Community

3
Bugzilla
CVE-2019-13720 chromium: chromium-browser: use-after-free in audio [fedora-all]2019-11-04
Bugzilla
CVE-2019-13720 chromium: chromium-browser: use-after-free in audio [epel-7]2019-11-04
Bugzilla
CVE-2019-13720 chromium-browser: use-after-free in audio2019-11-04