SecPod

Learn Search

Search across all Learn content

← Back to Security Research
ALERT:Google fixes four critical  Chrome vulnerabilities

ALERT:Google fixes four critical Chrome vulnerabilities

Sep 22, 2019By Vidita V Koushik2 min read

Google has released urgent updates for 4 vulnerabilities. One of the vulnerability is rated Critical and the other three are rated High in severity. Google fixes four chrome security vulnerabilities using a vulnerability management tool. However, as per the Chrome advisory, the vulnerabilities are :

  • CVE-2019-13685 : A critical Use-after-free issue in UI.
  • CVE-2019-13688 :  A Use-after-free issue in media.
  • CVE-2019-13687 :  A Use-after-free issue in media.
  • CVE-2019-13686 :  A Use-after-free issue in offline pages.

It is interesting to note that all the four vulnerabilities in Chrome are Use-after-free issues. A Use-after-free, identified as CWE-416 by Mitre, is an attempt to access a memory block after it has been freed which can lead to a direct memory crash, usage of unexpected values or execution of arbitrary code. This memory crash can be patched using a patch management tool.

An attacker who tries to exploit these vulnerabilities can disclose sensitive information, bypass security restrictions, crash the application or even execute arbitrary code in the context of the browser by redirecting them to a specially crafted webpage.

Chrome has released security updates for these vulnerabilities. Also, the Chrome security team has not yet disclosed the complete details of the vulnerabilities to prevent any cases of exploitation. The details would soon be available when a majority of the users have updated to the latest versions of Chrome.

Affected Products

Google Chrome versions before 77.0.3865.90

Impact

Successful exploitation allows an unprivileged attacker to remotely execute code, leak sensitive data or cause denial of service condition.

Solution

Please refer to this KB Articlewhich is now replaced by KB Articleto apply the patches using SanerNow.

Featured Posts

Open StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores
StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores

CVE Research

StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores

StyleSmuggler, an unpatched Magento and Adobe Commerce flaw letting attackers execute code without authentication via log poisoning, installing a persistent Linux backdoor that has already compromised live stores with no vendor patch available.

Sep 7, 2026

Open CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Flaw Enables Server Takeover
CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Vulnerability

CVE Research

CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Flaw Enables Server Takeover

Sep 7, 2026

Open Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212
Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE Research

Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE-2026-20212 is a critical vulnerability in Cisco Nexus 9000 Series Switches that use Silicon One ASICs. It allows an unauthenticated remote attacker to execute code with root privileges by sending crafted input to TCP ports 43210 and 43211, which are reachable in the default Layer 3 VRF. Exploitation can also crash the S1HAL process and force a device reload. This article covers how the vulnerability works, the affected product identifiers, its potential impact, available workarounds, and how to identify fixed software using the Cisco Software Checker.

Sep 4, 2026

Open SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution
SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

CVE Research

SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

Sep 3, 2026