ArchLinux: 201911-2: qt5-webengine: arbitrary code execution
Summary
A use-after-free vulnerability has been found in the audio component of the chromium browser before 78.0.3904.87. Google is aware of reports that an exploit for this vulnerability exists in the wild.
Resolution
Upgrade to 5.13.2-2.
# pacman -Syu "qt5-webengine>=5.13.2-2"
The problem has been fixed upstream but no release is available yet.
References
https://bugs.archlinux.org/task/64347 https://code.qt.io/cgit/qt/qtwebengine-chromium.git/patch/?id=d6e5fc10e417efdf8665d9fba57c269f0534072f https://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_31.html https://security.archlinux.org/CVE-2019-13720
Workaround
None.