CVE-2019-13669 describes an incorrect data validation vulnerability in Google Chrome versions prior to 77.0.3865.75, allowing a remote attacker to spoof the Omnibox (URL bar) content through a specially crafted HTML page. This is a medium-severity vulnerability with a CVSS score of 4.3, requiring user interaction (UI:R) via a crafted webpage, but without impacting confidentiality, integrity, or availability beyond the spoofing itself. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. While there's limited community discussion and media coverage, its low EPSS and FAUCET Risk Score suggest a low likelihood of widespread exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 77.0.3865.75CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.