Skip to content
COOEY

EXPOSURES › CVE-2019-13720

CVE-2019-13720

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-23 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-13720 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wildunpatchedransomware

A use-after-free vulnerability in Google Chrome's WebAudio component allowed remote attackers to exploit heap corruption via a crafted HTML page.

This use-after-free flaw in Chrome's WebAudio module enabled remote code execution through heap corruption, posing a severe risk to any organization relying on Chrome for web-based applications. DIBs must ensure Chrome is patched to the latest version immediately, as this vulnerability was actively exploited in the wild and linked to ransomware campaigns. Failure to patch leaves systems vulnerable to arbitrary code execution and potential data breaches.

Shame score — A critical use-after-free vulnerability in a widely used browser component was actively exploited in the wild and linked to ransomware, demonstrating severe negligence in patching and security monitoring.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chrome WebAudio contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized