PT-2019-3977 · Google+3 · Google Chrome+3

Alexey Kulaev

+1

·

Published

2019-10-31

·

Updated

2025-10-24

·

CVE-2019-13720

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 78.0.3904.87
Description The issue is related to a use after free in WebAudio, allowing a remote attacker to potentially exploit heap corruption via a crafted HTML page. This could impact the confidentiality, integrity, and availability of protected information. The vulnerability has been exploited in real-world attacks.
Recommendations For Google Chrome versions prior to 78.0.3904.87, update to version 78.0.3904.87 or later to resolve the issue. As a temporary workaround, consider restricting access to WebAudio components until the update is applied.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020_0902
ALSA-2020_1293
ALSA-2020_1317
ALSA-2021_4396
ALSA-2025_16880
ALT-PU-2019-3112
ALT-PU-2020-1050
ALT-PU-2020-1707
ALT-PU-2020-2441
BDU:2019-04508
CVE-2019-13720
DSA-4562-1
MGASA-2019-0320
OPENSUSE-SU-2019:2421-1
OPENSUSE-SU-2019:2426-1
OPENSUSE-SU-2019:2427-1
OPENSUSE-SU-2019:2447-1
OPENSUSE-SU-2019:2664-1
OPENSUSE-SU-2019_2421-1
OPENSUSE-SU-2019_2664-1
OPENSUSE-SU-2024:10681-1
OPENSUSE-SU-2024:12948-1
RHSA-2019:3775
RHSA-2019_3775

Affected Products

Alt Linux
Google Chrome
Red Hat
Suse