Vulnerability record · CVE-2019-13720 · published 25 November 2019
CVE-2019-13720: Google Chrome WebAudio use-after-free allows heap corruption
Google · Chrome
Google Chrome before 78.0.3904.87 contains a use-after-free in WebAudio that a remote attacker can trigger with a crafted HTML page, leading to heap corruption. The flaw is remotely reachable and requires the victim to load the page, making it a realistic drive-by target.
Description
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution potential, KEV listing, high EPSS, and a public exploit reference make this a high-priority patch despite the user-interaction requirement.
What it is
Google Chrome before 78.0.3904.87 contains a use-after-free in WebAudio that a remote attacker can trigger with a crafted HTML page, leading to heap corruption. The flaw is remotely reachable and requires the victim to load the page, making it a realistic drive-by target.
Impact
An attacker can corrupt the heap and potentially execute code in the browser process context, gaining the victim's privileges.
Attack surface
Reached over the network via a crafted HTML page rendered in Chrome; no authentication is needed but user interaction (loading the page) is required per the CVSS vector.
Exploitation
CISA added it to KEV on 2022-05-23, EPSS 30-day probability is about 0.73 (99.4th percentile), and a public Packet Storm exploit reference exists, indicating active exploitation.
What to do
- Update Chrome to 78.0.3904.87 or later, and apply the referenced openSUSE and Gentoo updates for bundled Chromium.
- Enforce automatic browser updates and verify version compliance across endpoints.
- Restrict or sandbox browser use for high-risk users and block untrusted web content where feasible.
- Monitor vendor advisories for follow-up fixes to the same WebAudio component.
Detection
- Hunt for Chrome versions below 78.0.3904.87 in asset inventory and endpoint telemetry.
- Alert on browser crashes or renderer process terminations tied to WebAudio activity.
- Review proxy and DNS logs for known exploit-hosting domains and suspicious HTML delivery.
- Correlate endpoint process creation from browser child processes with unusual memory or network behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-13720 to the Known Exploited Vulnerabilities catalog on 23 May 2022 as "Google Chrome WebAudio Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 13 June 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-13720 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-13720), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.