Researchers detailed two Chrome renderer exploitation chains that turned memory-corruption flaws into remote code execution from malicious web content. One write-up analyzed CVE-2020-15972, a use-after-free in Chrome's WebAudio component on Android, where removal of a mutex during orphaned AudioHandler cleanup let the audio processing thread access freed memory. The bug could be triggered through AudioWorkletNode and ScriptProcessorNode, enabling an out-of-bounds read for information disclosure, ASLR bypass, and eventual control of a virtual function call inside the renderer.
A separate analysis showed how the libwebp bug's limited 4-byte out-of-bounds write in Chrome Blink could be weaponized into full renderer RCE by abusing Chromium heap behavior. The researchers used CSSVariableData and PartitionAlloc ThreadCache placement to convert the write into a use-after-free, reclaimed the freed object with AudioArray to gain a heap out-of-bounds read, and then forged an HRTFPanner object to execute attacker-controlled code on Chromium running Ubuntu 22.04. Together, the reports show how attackers can chain information disclosure, allocator manipulation, and object corruption inside the Chrome renderer, while Google had already patched the WebAudio flaw in Chrome 86.0.4240.75.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
DARKNAVY published a technical write-up describing how a Chrome renderer libwebp out-of-bounds write could be turned into a CSSVariableData use-after-free, an AudioArray-based infoleak, and ultimately code execution via a forged HRTFPanner object.
GitHub Security Lab published a detailed analysis of exploiting CVE-2020-15972 from a malicious website to achieve remote code execution in the Chrome renderer on Android as part of a larger exploit chain.
Google fixed the Chrome WebAudio renderer remote code execution vulnerability CVE-2020-15972 in Chrome version 86.0.4240.75. The write-up states this occurred in October 2020.
The Chrome WebAudio use-after-free tracked as CVE-2020-15972 was reported in September 2020 as bug 1125635 and was treated as a duplicate of bug 1115901.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.