CVE-2019-13724: High severity google chrome (trace event) vulnerability
Out of bounds memory access in WebBluetooth in Google Chrome prior to 78.0.3904.108 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Other sources
Out-of-bounds access in Bluetooth.
References: https://chromereleases.googleblog.com/2019/11/stable-channel-update-for-desktop18.html https://bugs.chromium.org/p/chromium/issues/detail?id=1024116
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-13724?
CVE-2019-13724 is classified as a high severity vulnerability due to potential exploitation leading to heap corruption.
How do I fix CVE-2019-13724?
To fix CVE-2019-13724, update Google Chrome to version 78.0.3904.108 or later.
What type of vulnerability is CVE-2019-13724?
CVE-2019-13724 is an out of bounds memory access vulnerability in the WebBluetooth feature of Google Chrome.
Who can exploit CVE-2019-13724?
A remote attacker who has compromised the renderer process can exploit CVE-2019-13724 through a specially crafted HTML page.
On which versions of Google Chrome does CVE-2019-13724 affect?
CVE-2019-13724 affects Google Chrome versions prior to 78.0.3904.108.