PT-2019-5136 · Google+3 · Google Chrome+3

Sergei Glazunov

·

Published

2019-12-17

·

Updated

2024-06-15

·

CVE-2019-13767

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 79.0.3945.88
Description The issue is related to a use after free vulnerability in the media picker mechanism of Google Chrome, which can be exploited by a remote attacker who has compromised the renderer process. This can potentially lead to heap corruption via a crafted HTML page, allowing the attacker to gain unauthorized access to confidential data, cause a denial of service, and impact data integrity.
Recommendations For versions prior to 79.0.3945.88, update to version 79.0.3945.88 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially malicious HTML pages to minimize the risk of exploitation.

Fix

Use After Free

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1129
ALT-PU-2020-1171
ALT-PU-2020-1707
ALT-PU-2020-2441
BDU:2020-01803
CVE-2019-13767
DSA-4606-1
MGASA-2020-0078
OPENSUSE-SU-2019:2712-1
OPENSUSE-SU-2019_2712-1
OPENSUSE-SU-2020:0007-1
OPENSUSE-SU-2024:10681-1
OPENSUSE-SU-2024:12948-1
RHSA-2020:0005
RHSA-2020_0005

Affected Products

Alt Linux
Google Chrome
Red Hat
Suse