CVE-2019-13700: High severity google chrome (trace event) vulnerability
Published Nov 25, 2019
·Updated
Out of bounds memory access in the gamepad API in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Affected Software
2 affected components
Google Chrome<78.0.3904.70
openSUSE Backports=15.0-sp1
Event History
Nov 25, 2019
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
DescriptionWeakness
Frequently Asked Questions
1
What must an attacker achieve before this flaw can be exploited?
The attacker must have compromised the Chrome renderer process and use a crafted HTML page to trigger heap corruption through the Gamepad API. The CVSS vector also indicates that user interaction is required.
2
How can I determine whether a Chrome installation is affected?
Google Chrome versions earlier than 78.0.3904.70 are affected. Check the installed Chrome version and update any installation below that version.