CVE-2019-13677 describes a medium-severity vulnerability in Google Chrome versions prior to 77.0.3865.75, where insufficient policy enforcement in site isolation allowed a remote attacker to bypass this security feature through a specially crafted HTML page. This vulnerability has a CVSS score of 6.5, indicating a network-based attack requiring user interaction, with a high impact on confidentiality. Despite its potential, there is no evidence of active exploitation, no public exploit code available (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, suggesting low current threat activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 77.0.3865.75CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.