CVE-2019-13765: Use After Free
Published Oct 22, 2019
·Updated
Use-after-free in content delivery manager in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected Software
2 affected componentsFixes available
Google Chrome<78.0.3904.70
78.0.3904.70
Google Chrome<78.0.3904.70
Event History
Oct 22, 2019
CVE Published
12:00 AM
Jan 3, 2020
CVE Published
via MITRE·10:35 PM
Data Sourced
via MITRE·10:35 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
Which Chrome installations should be considered affected?
Google Chrome versions earlier than 78.0.3904.70 are affected.
2
What must an attacker do to exploit this issue?
An attacker can attempt exploitation remotely by getting a user to interact with a crafted HTML page. No attacker privileges are required.