CVE-2019-13682 is a high-severity vulnerability affecting Google Chrome versions prior to 77.0.3865.75, stemming from insufficient policy enforcement in external protocol handling. A remote attacker could exploit this by tricking a user into visiting a crafted HTML page, bypassing the same-origin policy and potentially leading to high impact on confidentiality, integrity, and availability. While the CVSS score is 8.8, there is no evidence of active exploitation, readily available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, suggesting a low current threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 77.0.3865.75CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.