Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published: 2019-11-01
Though details are scant, Google released a patch for a Google Chrome vulnerability that has been exploited in the wild as a zero day. Background On October 31, Google published a Stable Channel Update for the desktop version of Google Chrome. This release fixes two vulnerabilities, one of which has been exploited in the wild as a zero day.
https://security.gentoo.org/glsa/202004-04
http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00022.html
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-13720
https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-5139
https://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_31.html
http://packetstormsecurity.com/files/167066/Google-Chrome-78.0.3904.70-Remote-Code-Execution.html