CVE-2019-13720
HIGH KEVGoogle Chrome <78.0.3904.87 - Use After Free
Title source: llmDescription
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Exploits (5)
exploitdb
WORKING POC
by Forrest Orr · javascriptremotemultiple
https://www.exploit-db.com/exploits/50917
References (6)
Scores
CVSS v3
8.8
EPSS
0.8823
EPSS Percentile
99.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation Intel
CISA KEV
2022-05-23
VulnCheck KEV
2019-10-29
InTheWild.io
2019-10-29
ENISA EUVD
EUVD-2019-5139
Classification
CWE
CWE-416
Status
published
Affected Products (2)
google/chrome
< 78.0.3904.87
opensuse/leap
Timeline
Published
Nov 25, 2019
KEV Added
May 23, 2022
Tracked Since
Feb 18, 2026