CVE-2019-5870
published 2019-11-25CVE-2019-5870: Use after free in media in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
PriorityP346critical9.6CVSS 3.1
AVNACLPRNUIRSCCHIHAH
EPSS
1.44%
70.2th percentile
Use after free in media in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| debian | chromium | < chromium 78.0.3904.87-1 (bookworm) | chromium 78.0.3904.87-1 (bookworm) |
| chrome | < 77.0.3865.75 | 77.0.3865.75 | |
| chrome | >= unspecified < 77.0.3865.75 | 77.0.3865.75 | |
| chrome_desktop | — | — |
CVSS provenance
nvdv3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.6CRITICAL
vendor_debian9.6CRITICAL
vendor_redhat9.6CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2019-5870
vendor_chrome·2019-09-10·CVSS 6.5
CVE-2019-5870 [CRITICAL] Stable Channel Update for Desktop: CVE-2019-5870
Stable Channel Update for Desktop
CVE-2019-5870: Use-after-free in media. Reported by Guang Gong of Alpha Team, Qihoo 360 on 2019-08-29
[$10000][ 989969 ] Critical CVE-2019-13766: Use-after-free in accessibility
Reported by Pawel Wylecial of REDTEAM
Severity: critical
Red Hat
chromium-browser: Use-after-free in media
vendor_redhat·2019-09-10·CVSS 9.6
CVE-2019-5870 [CRITICAL] chromium-browser: Use-after-free in media
chromium-browser: Use-after-free in media
Use after free in media in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Debian
CVE-2019-5870: chromium - Use after free in media in Google Chrome prior to 77.0.3865.75 allowed a remote ...
vendor_debian·2019·CVSS 9.6
CVE-2019-5870 [CRITICAL] CVE-2019-5870: chromium - Use after free in media in Google Chrome prior to 77.0.3865.75 allowed a remote ...
Use after free in media in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved (fixed in 78.0.3904.87-1)
GHSA
GHSA-9743-23p2-9v8j: Use after free in media in Google Chrome prior to 77
ghsa_unreviewed·2022-05-24
CVE-2019-5870 [MEDIUM] GHSA-9743-23p2-9v8j: Use after free in media in Google Chrome prior to 77
Use after free in media in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Project0
Déjà vu-lnerability - Project Zero
project_zero·2021-02-01
CVE-2014-9665 Déjà vu-lnerability - Project Zero
A Year in Review of 0-days Exploited In-The-Wild in 2020
Posted by Maddie Stone, Project Zero
2020 was a year full of 0-day exploits. Many of the Internet’s most popular browsers had their moment in the spotlight. Memory corruption is still the name of the game and how the vast majority of detected 0-days are getting in. While we tried new methods of 0-day detection with modest success, 2020 showed us that there is still a long way to go in detecting these 0-day exploits in-the-wild. But what may be the most notable fact is that 25% of the 0-days detected in 2020 are closely related to previously publicly disclosed vulnerabilities. In other words, 1 out of every 4 detected 0-day exploits could potentially have been avoided if a more thorough investigation and patching effort were explor
OSV
CVE-2019-5870: Use after free in media in Google Chrome prior to 77
osv·2019-11-25·CVSS 9.6
CVE-2019-5870 [CRITICAL] CVE-2019-5870: Use after free in media in Google Chrome prior to 77
Use after free in media in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Project0
Project Zero RCA: CVE-2020-6572: Chrome MediaCodecAudioDecoder Sandbox Escape
project_zero·CVSS 8.8
CVE-2020-6572 [HIGH] Project Zero RCA: CVE-2020-6572: Chrome MediaCodecAudioDecoder Sandbox Escape
# CVE-2020-6572: Chrome MediaCodecAudioDecoder Sandbox Escape
*Ben Hawkes, Project Zero*
## The Basics
**Disclosure or Patch Date:** 7 April 2020
**Product:** Google Chrome
**Advisory:** https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
**Affected Versions:** pre 81.0.4044.92
**First Patched Version:** 81.0.4044.92
**Issue/Bug Report:** https://bugs.chromium.org/p/chromium/issues/detail?id=1066893
**Patch CL:** https://chromium.googlesource.com/chromium/src.git/+/c0268599d1161f4c57a7911c7f036f70af88c8d0
**Bug-Introducing CL:** https://source.chromium.org/chromium/chromium/src/+/2864f6e586bc2eba6b7479fee7738a0a2779dd0f (Commited on 2016-03-23)
**Reporter(s):** Anonymous
## The Code
**Proof-of-concept:** N/A
**Exploit sample:** N/A
**Did you
No detection rules found.
No public exploits indexed.
2019-11-25
Published