First published: Wed Jan 16 2019(Updated: )
Use after free in FileAPI in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chrome security severity: High)
Credit: Mark Brand Google Project Zero chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome (Trace Event) | <72.0.3626.81 | 72.0.3626.81 |
Google Chrome (Trace Event) | <72.0.3626.81 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2019-13768 is classified as High.
To fix CVE-2019-13768, update Google Chrome to version 72.0.3626.81 or later.
CVE-2019-13768 affects Google Chrome versions prior to 72.0.3626.81.
CVE-2019-13768 is a use after free vulnerability in the FileAPI of Google Chrome.
Yes, CVE-2019-13768 allows a remote attacker to potentially perform a sandbox escape via a crafted HTML page.