CVE-2019-13767 is a high-severity use-after-free vulnerability in Google Chrome's media picker, affecting versions prior to 79.0.3945.88, as well as Debian, Fedora, and OpenSUSE distributions. An unauthenticated remote attacker could exploit this by tricking a user into visiting a crafted HTML page, potentially leading to heap corruption and full compromise of the renderer process with high impact on confidentiality, integrity, and availability. While the vulnerability has a high FAUCET Risk Score of 81/100 and some community discussion, there is no evidence of active exploitation, nor are public exploit codes available in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 79.0.3945.88CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.