Junglewise Threat Intelligence

CVE-2019-13720: Google Chrome WebAudio Use-After-Free Vulnerability

CVE-2019-13720 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-05-23

Technologies: Google Chrome. Vendors: Google.

Executive brief

A use-after-free vulnerability exists in the WebAudio component of Google Chrome. A remote attacker can exploit this flaw by enticing a user to visit a specially crafted HTML page, potentially leading to heap corruption and arbitrary code execution.

Affected products

  • Google Chrome prior to 78.0.3904.87

Timeline

  • 2019-10-31: patched: Stable channel update 78.0.3904.87 released.
  • 2019-11-25: disclosed: NVD Published Date.
  • 2022-05-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-05-23: exploited: Reported as exploited in the wild.