CVE-2019-13698 describes an out-of-bounds memory access vulnerability in Google Chrome versions prior to 73.0.3683.103, specifically within its JavaScript engine. This flaw, rated 8.8 HIGH (CVSSv3.1), allows a remote attacker to potentially exploit heap corruption and achieve high impact to confidentiality, integrity, and availability by enticing a user to visit a crafted HTML page. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not listed in CISA's KEV catalog, its community discussion and media coverage indicate some awareness, though it is not currently considered actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 73.0.3683.103CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.