CVE-2019-13720 is a high-severity use-after-free vulnerability in Google Chrome's WebAudio component, affecting versions prior to 78.0.3904.87, as well as Google Leap and OpenSUSE Chrome/Leap. This flaw allows a remote attacker to achieve heap corruption and potentially execute arbitrary code by enticing a user to visit a specially crafted HTML page. With a CVSS score of 8.8, it poses a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. This vulnerability has been actively exploited in the wild, notably in "Operation WizardOpium" attacks, and has garnered substantial community discussion and media coverage, indicating its critical nature.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 78.0.3904.87CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.