漏洞描述
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
chromereleases.googleblog.comhttps://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_31.html↗packetstormsecurity.comhttp://packetstormsecurity.com/files/167066/Google-Chrome-78.0.3904.70-Remote-Code-Execution.html↗lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2019-12/msg00022.html↗security.gentoo.orghttps://security.gentoo.org/glsa/202004-04↗crbug.comhttps://crbug.com/1019226↗