References https://nvd.nist.gov/vuln/detail/CVE-2019-13720 https://googleprojectzero.github.io/0days-in-the-wild/0day-RCAs/2019/CVE-2019-13720.html https://www.cve.org/CVERecord?id=CVE-2019-13720 https://securelist.com/chrome-0-day-exploit-cve-2019-13720-used-in-operation-wizardopium/94866/ https://www.cnvd.org.cn/flaw/show/CNVD-2019-40304 https://electronjs.org/zh/blog/cve-2019-13720 https://www.anquanke.com/post/id/208124 https://access.redhat.com/security/cve/cve-2019-13720 https://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_31.html https://cve.imfht.com/poc_detail/1bfed7bbaf7a6cc3f15e2403d4e92ad545e5de8f
Related VulnerabilitiesPoCgoogle-api-key: Google API KeyPoCCVE-2026-71209: Audiobookshelf - Authentication BypassAudiobookshelf /api 未授权访问漏洞(CVE-2026-71209)WP Google 地图 < 9.0.48 - 未经身份验证的存储 XSS (CVE-2025-11307)PoCCVE-2026-8732: WP Maps Pro (wp-google-map-gold) <= 6.1.0 - Unauthenticated Administrator Account CreationPoCCVE-2026-8679: WordPress AudioIgniter <= 2.0.2 - Unauthenticated IDORAudioIgniter / 信息泄露漏洞(CVE-2026-8679)PoCCVE-2026-4810: Google ADK-Python - Unauthenticated Builder EndpointWordPress Plugin Mayosis Core /wp-content/plugins/mayosis-core/library/wave-audio/peaks/remote_dl.php 文件读取漏洞 (CVE-2025-1565)PoCgoogle-gemini-key-exposure: Google Gemini API Key - ExposurePoCCVE-2024-13220: WordPress Google Map Professional - Cross-Site ScriptingPoCfreshrss-api: FreshRSS Google Reader API ExposurePoCgcloudignore-file-exposure: Google Cloud Ignore File Exposure