{"id":"CVE-2019-13720","aliases":[],"url":"https://o3.security/vulnerability/CVE-2019-13720","summary":null,"details":"Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.","published":"2019-11-25T15:15:33.887Z","modified":"2026-04-16T04:31:25.426136825Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":{"score":0.72977,"percentile":0.99416,"asOf":"2026-09-08"},"cisaKev":null,"exploitsKnown":10,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-13720"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00022.html"},{"type":"ADVISORY","url":"https://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_31.html"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202004-04"},{"type":"REPORT","url":"https://crbug.com/1019226"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/167066/Google-Chrome-78.0.3904.70-Remote-Code-Execution.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-16T04:31:25.426136825Z"}}