Google Chrome 79.0.3945.79 corrected 51 security issues, including critical Bluetooth and Password Manager bugs and several SQLite Full-Text Search (FTS3/FTS4) defects. The SQLite fixes address crafted-data handling failures such as an out-of-bounds write in CVE-2019-13734 and out-of-bounds reads in CVE-2019-13752 and CVE-2019-13753; the latter affects fts3IncrmergePush and depends on the CVE-2019-13752 correction. Chromium backported upstream changes that improve shadow-table corruption validation, prevent infinite recursion, and remove unsafe reachable FTS3 logic.
Red Hat shipped the Chromium fixes for RHEL 6 Supplementary in RHSA-2019:4238, updating chromium-browser to 79.0.3945.79-1.el6_10; affected users must restart Chromium after installation. CVE-2019-13752 could allow a remote attacker to induce interaction with a crafted HTML page and potentially disclose process-memory contents. Red Hat subsequently included SQLite fixes in RHSA-2020:1810 for RHEL 8 through sqlite-3.26.0-6.el8; RHEL 5 and 6 standalone SQLite were not affected, while affected RHEL 7 SQLite was not scheduled for a fix.

See affected versions and whether adversaries are exploiting it.
13 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued important-security advisory RHSA-2020:2014 for RHEL 7.6 product streams, providing SQLite 3.7.17-8.el7_6.1 packages to remediate CVE-2019-13734, an FTS3 shadow-table corruption-detection issue. The update covered RHEL 7.6 EUS, AUS, TUS, SAP, Compute Node, and multiple hardware architectures.
Red Hat issued RHBA-2020:0547 to remediate CVE-2019-13734 in affected Ansible Tower 3.4, 3.5, and 3.7 memcached packages for RHEL 7.
Red Hat issued important-security advisory RHSA-2020:0273 for RHEL 8, updating SQLite to remediate CVE-2019-13734, an FTS3 shadow-table corruption-detection issue. The update applied across supported RHEL 8 architectures and subscription variants.
Red Hat issued important-security advisory RHSA-2020:0229 for RHEL 8.0 Update Services for SAP Solutions, providing SQLite 3.26.0-4.el8_0 packages to remediate CVE-2019-13734. The update covered x86_64 and ppc64le SAP Solutions variants.
Red Hat issued important-security advisory RHSA-2020:0227 for RHEL 7, updating SQLite to version 3.7.17-8.el7_7.1 and remediating CVE-2019-13734, an FTS3 shadow-table corruption-detection issue. The update covered supported RHEL 7 product variants and x86_64, s390x, ppc64, and ppc64le architectures.
Red Hat's analysis noted that no released standalone SQLite version yet contained the upstream fixes for the FTS3 shadow-table corruption issues underlying CVE-2019-13752, CVE-2019-13753, and CVE-2019-13734.
Red Hat issued critical advisory RHSA-2019:4238 for RHEL 6 Supplementary, updating chromium-browser to 79.0.3945.79-1.el6_10 and remediating 39 CVEs, including the Chromium SQLite flaws.
Pedro Sampaio reported CVE-2019-13734, an out-of-bounds write in Chromium's bundled SQLite component, and CVE-2019-13752, an out-of-bounds read related to FTS3 shadow-table corruption detection.
Sergei Glazunov of Google Project Zero reported CVE-2019-13726, a critical heap-buffer-overflow vulnerability in Chrome Password Manager.
SQLite committed further FTS3 shadow-table corruption-detection improvements, including validation of incremental-merge root-node height and returning FTS_CORRUPT_VTAB for invalid metadata. The change also added debug/test merge-count configurability and updated fuzzing test data.
Gengming Liu and Jianyu Chen of Tencent Keen Security Lab reported CVE-2019-13725, a critical use-after-free vulnerability in Chrome's Bluetooth functionality.
Red Hat issued moderate-severity RHSA-2020:1810 for RHEL 8, providing SQLite 3.26.0-6.el8 and fixing seven vulnerabilities, including CVE-2019-13752 and CVE-2019-13753.
Google released a Chrome update addressing 51 security issues, including critical CVE-2019-13725 in Bluetooth and CVE-2019-13726 in Password Manager, as well as high-severity WebSockets, V8, WebAudio, and SQLite flaws.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
14 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcechromereleases.googleblog.com
Open sourcegithub.com
Open sourcechromium.googlesource.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.