CVE-2019-13720: Google Chrome WebAudio Use-After-Free Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2022-05-23. EPSS: 49.4% chance of exploitation in the next 30 days.

Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Affected products

  • Google Chrome: before 78.0.3904.87 (fixed in 78.0.3904.87)
  • Opensuse Leap: version 15.1 only

Published 2019-11-25. Last modified 2026-06-17.