CVE-2019-13703 describes an insufficient policy enforcement vulnerability in the Omnibox of Google Chrome on Android, affecting versions prior to 78.0.3904.70, as well as related Google and openSUSE products. This medium-severity vulnerability (CVSS 4.3) allows a remote attacker to spoof the URL bar's contents through a specially crafted HTML page, requiring user interaction but with low attack complexity. While there is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and it is not on the KEV catalog, the vulnerability has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 78.0.3904.70CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.