CVE-2019-13764
published 2019-12-10CVE-2019-13764: Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
PriorityP350high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
6.43%
92.9th percentile
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 79.0.3945.79-1 | 79.0.3945.79-1 |
| chromium | chromium | >= 0 < 79.0.3945.79-1 | 79.0.3945.79-1 |
| chromium | chromium | >= 0 < 79.0.3945.79-1 | 79.0.3945.79-1 |
| chromium | chromium | >= 0 < 79.0.3945.79-1 | 79.0.3945.79-1 |
| debian | chromium | < chromium 79.0.3945.79-1 (bookworm) | chromium 79.0.3945.79-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome | < 79.0.3945.79 | 79.0.3945.79 | |
| chrome | >= unspecified < 79.0.3945.79 | 79.0.3945.79 | |
| chrome_chrome | — | — | |
| opensuse | backports_sle | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2019-13764 is a Type Confusion vulnerability in the V8 JavaScript engine component of Google Chrome, exploitable via a crafted HTML page delivered remotely ↗
- →The vulnerability is specifically in the V8 component (JavaScript engine); detection should focus on V8-related crash telemetry or heap corruption signals in Chrome processes prior to version 79.0.3945.79 ↗
- ·The upstream Chromium bug tracker issue referenced (id=102886) may contain additional technical details or a proof-of-concept, but the bug may be access-restricted ↗
- ·Fixed version is 79.0.3945.79; any Chrome/Chromium instance below this version is vulnerable to this Type Confusion in V8 ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8fwf-6328-m3pr: Type confusion in JavaScript in Google Chrome prior to 79
ghsa_unreviewed·2022-05-24
CVE-2019-13764 [MEDIUM] CWE-843 GHSA-8fwf-6328-m3pr: Type confusion in JavaScript in Google Chrome prior to 79
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Project0
Déjà vu-lnerability - Project Zero
project_zero·2021-02-01
CVE-2014-9665 Déjà vu-lnerability - Project Zero
A Year in Review of 0-days Exploited In-The-Wild in 2020
Posted by Maddie Stone, Project Zero
2020 was a year full of 0-day exploits. Many of the Internet’s most popular browsers had their moment in the spotlight. Memory corruption is still the name of the game and how the vast majority of detected 0-days are getting in. While we tried new methods of 0-day detection with modest success, 2020 showed us that there is still a long way to go in detecting these 0-day exploits in-the-wild. But what may be the most notable fact is that 25% of the 0-days detected in 2020 are closely related to previously publicly disclosed vulnerabilities. In other words, 1 out of every 4 detected 0-day exploits could potentially have been avoided if a more thorough investigation and patching effort were explor
Project0
In-the-Wild Series: Chrome Infinity Bug - Project Zero
project_zero·2021-01-01
CVE-2019-13764 In-the-Wild Series: Chrome Infinity Bug - Project Zero
This is part 2 of a 6-part series detailing a set of vulnerabilities found by Project Zero being exploited in the wild. To read the other parts of the series, see the introduction post.
Posted by Sergei Glazunov, Project Zero
This post only covers one of the exploits, specifically a renderer exploit targeting Chrome 73-78 on Android. We use it as an opportunity to talk about an interesting vulnerability class in Chrome’s JavaScript engine.
## Brief introduction to typer bugs
One of the features that make JavaScript code especially difficult to optimize is the dynamic type system. Even for a trivial expression like a + b the engine has to support a multitude of cases depending on whether the parameters are numbers, strings, booleans, objects, etc. JIT compilation wouldn’t make much se
Project0
In-the-Wild Series: Chrome Exploits - Project Zero
project_zero·2021-01-01·CVSS 8.8
CVE-2017-5070 [HIGH] In-the-Wild Series: Chrome Exploits - Project Zero
This is part 3 of a 6-part series detailing a set of vulnerabilities found by Project Zero being exploited in the wild. To read the other parts of the series, see the introduction post.
Posted by Sergei Glazunov, Project Zero
## Introduction
As we continue the series on the watering hole attack discovered in early 2020, in this post we’ll look at the rest of the exploits used by the actor against Chrome. A timeline chart depicting the extracted exploits and affected browser versions is provided below. Different color shades represent different exploit versions.
All vulnerabilities used by the attacker are in V8, Chrome’s JavaScript engine; and more specifically, they are JIT compiler bugs. While classic C++ memory safety issues are still exploited in real-world attacks against we
OSV
CVE-2019-13764: Type confusion in JavaScript in Google Chrome prior to 79
osv·2019-12-10·CVSS 8.8
CVE-2019-13764 [HIGH] CVE-2019-13764: Type confusion in JavaScript in Google Chrome prior to 79
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Chrome
Stable Channel Update for Desktop: CVE-2019-13764
vendor_chrome·2019-12-10·CVSS 8.8
CVE-2019-13764 [HIGH] Stable Channel Update for Desktop: CVE-2019-13764
Stable Channel Update for Desktop
CVE-2019-13764: Type Confusion in V8. Reported by Soyeon Park and Wen Xu at SSLab, Georgia Tech on 2019-11-26
[$7500][ 1020899 ] Medium CVE-2019-13736: Integer overflow in PDFium
Reported by Anonymous on 2019-11-03
Severity: high
Red Hat
chromium-browser: Type Confusion in V8
vendor_redhat·2019-12-10·CVSS 8.8
CVE-2019-13764 [HIGH] chromium-browser: Type Confusion in V8
chromium-browser: Type Confusion in V8
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Debian
CVE-2019-13764: chromium - Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a re...
vendor_debian·2019·CVSS 8.8
CVE-2019-13764 [HIGH] CVE-2019-13764: chromium - Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a re...
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 79.0.3945.79-1)
bullseye: resolved (fixed in 79.0.3945.79-1)
forky: resolved (fixed in 79.0.3945.79-1)
sid: resolved (fixed in 79.0.3945.79-1)
trixie: resolved (fixed in 79.0.3945.79-1)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-12/msg00036.htmlhttps://access.redhat.com/errata/RHSA-2019:4238https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.htmlhttps://crbug.com/1028863https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2Z5M4FPUMDNX2LDPHJKN5ZV5GIS2AKNU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N5CIQCVS6E3ULJCNU7YJXJPO2BLQZDTK/https://seclists.org/bugtraq/2020/Jan/27https://security.gentoo.org/glsa/202003-08https://www.debian.org/security/2020/dsa-4606http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-12/msg00036.htmlhttps://access.redhat.com/errata/RHSA-2019:4238https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.htmlhttps://crbug.com/1028863https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2Z5M4FPUMDNX2LDPHJKN5ZV5GIS2AKNU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N5CIQCVS6E3ULJCNU7YJXJPO2BLQZDTK/https://seclists.org/bugtraq/2020/Jan/27https://security.gentoo.org/glsa/202003-08https://www.debian.org/security/2020/dsa-4606
2019-12-10
Published