CVE-2019-13715 describes an insufficient input validation vulnerability in the Omnibox component of Google Chrome versions prior to 78.0.3904.70, affecting Google Chrome and openSUSE distributions. This medium-severity flaw (CVSS 4.3) allows a remote attacker to perform domain spoofing using IDN homographs through a crafted domain name, requiring user interaction but with low attack complexity and impacting integrity. There is no evidence of active exploitation, publicly available exploit code, or inclusion in CISA's KEV catalog, though it received limited community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 78.0.3904.70CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.