LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-13720: Google Chrome WebAudio Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 23, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 13, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-13720 to its Known Exploited Vulnerabilities catalog on May 23, 2022, with a federal patch deadline of Jun 13, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Google Chrome WebAudio contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2019-13720 is a use-after-free vulnerability in the WebAudio component of Google Chrome. A remote attacker can trigger it with a crafted HTML page and potentially corrupt heap memory. For IT and security teams this matters because browsers are ubiquitous endpoints; successful exploitation can lead to code execution in the browser process and further compromise of the user session or host. Confirm all version and fix details against the vendor advisory.

How it works

The weakness is CWE-416, use-after-free. In this class of flaw, memory is freed while a pointer to it remains live; later use of that dangling pointer can corrupt the heap. According to the CISA summary, Google Chrome WebAudio contains such a vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. An attacker would typically lure a user to open or render the malicious page inside a vulnerable Chrome instance. Exact exploit mechanics, heap layout details, and any required user interaction beyond loading the page are not provided in the available facts and must be confirmed against the vendor advisory. No ransomware use is documented for this CVE.

Am I affected? How to find it in your systems

Google Chrome is commonly installed on Windows, macOS, and Linux workstations, VDI images, and some managed kiosks. WebAudio is a standard browser feature used for audio processing in web content, so the vulnerable code path is present in normal Chrome installations that include that component.

How to remediate

Patch first. Apply the Chrome updates per vendor instructions, as required by CISA. Deploy the update through your normal browser update channel, enterprise management console, or OS package mechanism, then verify the installed version matches the remediated build listed by the vendor.

If you can't patch immediately

Reduce exposure until the vendor update can be applied.

If your data may have been exposed

Actively exploited browser vulnerabilities can lead to session theft, credential harvesting, or host compromise and subsequent data exposure. If you suspect exploitation, isolate affected endpoints, preserve memory and disk evidence, rotate credentials that may have been accessible from the browser, and follow your incident-response plan. You can run a free exposure scan of your email addresses against known breach data to check whether associated accounts appear in prior breaches while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGoogle · Chrome WebAudio
WeaknessCWE-416
Added to CISA KEVMay 23, 2022
Federal patch deadlineJun 13, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities