CVE-2019-13705 is a medium-severity vulnerability affecting Google Chrome prior to version 78.0.3904.70, as well as related backports. It stems from insufficient policy enforcement in extensions, allowing a malicious extension to leak cross-origin data if a user is tricked into installing it. The attack requires user interaction (UI:R) and has low impact on confidentiality (C:L), with no integrity or availability impact. There is no evidence of active exploitation, nor are there public exploit modules or proof-of-concept code available, despite some community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 78.0.3904.70CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
sle-15CPE matchmatch criteria | cpe:2.3:o:opensuse:backports:sle-15:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.