CVE-2019-13674 describes an IDN spoofing vulnerability in Google Chrome versions prior to 77.0.3865.75. This flaw allowed a remote attacker to perform domain spoofing in the Omnibox using crafted domain names that leverage IDN homographs. Rated as Medium severity (CVSS 4.3), the vulnerability requires user interaction (UI:R) and could lead to low impact on integrity (I:L) by deceiving users about the legitimate website they are visiting. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion, and it is not listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 77.0.3865.75CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.