Candidate: CVE-2019-13747 PublicDate: 2019-12-10 22:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13747 https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html https://crbug.com/1018528 Description: Uninitialized data in rendering in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Ubuntu-Description: Notes: amurray| This only affects Android, so chromium-browser on Ubuntu is not-affected Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_chromium-browser: upstream_chromium-browser: released (79.0.3945.79) precise/esm_chromium-browser: DNE trusty_chromium-browser: ignored (out of standard support) trusty/esm_chromium-browser: DNE xenial_chromium-browser: not-affected bionic_chromium-browser: not-affected disco_chromium-browser: not-affected eoan_chromium-browser: not-affected devel_chromium-browser: not-affected