CVE-2019-13713 is a medium-severity vulnerability in Google Chrome (prior to version 78.0.3904.70) and related products, stemming from insufficient policy enforcement in JavaScript that allows cross-origin data leakage via a crafted HTML page. An unauthenticated attacker could exploit this remotely with low complexity, requiring user interaction, to achieve high confidentiality impact. While the vulnerability has garnered some community discussion and media coverage, there is no evidence of active exploitation, nor is public exploit code available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 78.0.3904.70CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
sle-15CPE matchmatch criteria | cpe:2.3:o:opensuse:backports:sle-15:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.