CVE-2019-13768Use After Free in Google Chrome

CWE-416Use After Free4 documents4 sources
Severity
7.4HIGHNVD
EPSS
1.6%
top 18.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 2
Latest updateJan 3

Description

Use after free in FileAPI in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chrome security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:NExploitability: 2.8 | Impact: 4.0

Affected Packages4 packages

CVEListV5google/chromeunspecified72.0.3626.81
NVDgoogle/chrome< 72.0.3626.81
debiandebian/chromium< chromium 72.0.3626.81-1 (bookworm)
Debianchromium/chromium< 72.0.3626.81-1+3

🔴Vulnerability Details

2
GHSA
GHSA-m523-mm9v-684f: Use after free in FileAPI in Google Chrome prior to 722023-01-03
OSV
CVE-2019-13768: Use after free in FileAPI in Google Chrome prior to 722023-01-02

📋Vendor Advisories

1
Debian
CVE-2019-13768: chromium - Use after free in FileAPI in Google Chrome prior to 72.0.3626.81 allowed a remot...2019