ZeroHour

CVE-2019-13720

KEV PoC mass

Use-After-Free in Google Chrome WebAudio Allows Heap Corruption (Actively Exploited)

CISA: Google Chrome WebAudio Use-After-Free Vulnerability

CVSS 3.1
8.8 high
EPSS
73%p99
Published
()
KEV added
AI analysis

CVE-2019-13720 is a use-after-free (CWE-416) in the WebAudio component of Google Chrome that exists in all releases prior to 78.0.3904.87. A remote attacker can trigger the flaw by luring a user to a crafted HTML page, corrupting the heap when the browser processes audio through the freed memory. Successful exploitation can lead to remote code execution with high impact on confidentiality, integrity, and availability, and a public proof-of-concept for Chrome 78.0.3904.70 is available. The flaw affects desktop and mobile users running vulnerable Chrome builds as well as the Chromium package shipped for openSUSE Leap. Exploitation is confirmed in the wild: Google fixed it as an actively exploited issue in November 2019, it was used in the Operation WizardOpium attacks, and it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-23.

What to do: Upgrade Google Chrome to 78.0.3904.87 or later (check the current version via the browser's About/Help page) and update the Chromium package on openSUSE Leap using the distribution's update channels. Because this flaw is triggered via a crafted web page and there are no reliable configuration workarounds, prioritizing browser patching across all endpoints is the key mitigation. Defenders should also review whether any user activity coincided with the Operation WizardOpium campaign, as this bug was chained in active attacks.

Affected
google chromeall versions prior to 78.0.3904.87 (vulnerable builds include 78.0.3904.70 and earlier)
opensuse leap
Estimated exposure
masshundreds of millions to billions of Chrome installations worldwide (Chrome is the dominant web browser) — Chrome has long held the largest global browser market share (roughly two-thirds of desktop usage), so the number of users on builds prior to 78.0.3904.87 was plausibly in the hundreds of millions or more, though the exact count of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chrome WebAudio
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googleopensuse
Products
chrome, leap
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news