CVE-2019-13699: URL spoof in navigation.
Published Aug 27, 2019
·Updated
Use after free in media in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Credit
David Erceg
Affected Software
3 affected componentsFixes available
Google Chrome<78.0.3904.70
78.0.3904.70
Google Chrome<78.0.3904.70
openSUSE Backports=15.0-sp1
Event History
Aug 27, 2019
CVE Published
12:00 AM
Nov 25, 2019
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
A remote attacker must first compromise the Chrome renderer process. They can then use a crafted HTML page to potentially trigger heap corruption in the media component.
2
Which Chrome versions are affected?
Google Chrome versions prior to 78.0.3904.70 are affected.
3
Does exploitation require user interaction?
Yes. The CVSS vector indicates user interaction is required, and the described attack uses a crafted HTML page.
4
What is the impact if exploitation succeeds?
Successful exploitation could allow compromise of confidentiality, integrity, and availability, as reflected by the high CVSS impact ratings.