CVE-2019-13720: isaware of reports that an exploit for exists in the wild
Google Chrome WebAudio contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Other sources
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 78.0.3904.87
Event History
Frequently Asked Questions
What is the severity of CVE-2019-13720?
CVE-2019-13720 is considered a high severity vulnerability due to its potential to allow remote code execution through heap corruption.
How do I fix CVE-2019-13720?
To fix CVE-2019-13720, upgrade Google Chrome to version 78.0.3904.87 or later.
Who is affected by CVE-2019-13720?
CVE-2019-13720 affects users of Google Chrome prior to version 78.0.3904.87 and those utilizing Chrome WebAudio.
What type of vulnerability is CVE-2019-13720?
CVE-2019-13720 is classified as a use-after-free vulnerability affecting the WebAudio feature in Google Chrome.
What can a remote attacker do with CVE-2019-13720?
A remote attacker can potentially exploit CVE-2019-13720 to execute arbitrary code on a victim's machine through a specially crafted HTML page.