First published: Thu Oct 31 2019(Updated: )
Google Chrome WebAudio contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit: chrome-cve-admin@google.com chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <78.0.3904.87 | 78.0.3904.87 |
Google Chrome WebAudio | ||
Google Chrome | <78.0.3904.87 | |
openSUSE | =15.1 | |
<78.0.3904.87 | ||
=15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13720 is considered a high severity vulnerability due to its potential to allow remote code execution through heap corruption.
To fix CVE-2019-13720, upgrade Google Chrome to version 78.0.3904.87 or later.
CVE-2019-13720 affects users of Google Chrome prior to version 78.0.3904.87 and those utilizing Chrome WebAudio.
CVE-2019-13720 is classified as a use-after-free vulnerability affecting the WebAudio feature in Google Chrome.
A remote attacker can potentially exploit CVE-2019-13720 to execute arbitrary code on a victim's machine through a specially crafted HTML page.