The attack leverages a waterhole-style injection on a Korean-language news portal. A malicious JavaScript code was inserted in the main page, which in turn, loads a profiling script from a remote site. The vulnerability tries to exploit the bug in Google Chrome browser and the script checks if the browsers version is greater or equal to 65 (current Chrome version is 78) It could mean that the exploit authors have only worked on these versions (a previous exploitation stage checked for version 65 or newer) or that other exploits have been used in the past for older Chrome versions.”]
Source: https://securelist.com/chrome-0-day-exploit-cve-2019-13720-used-in-operation-wizardopium/94866/

