CVE-2019-13718 describes an insufficient data validation vulnerability in the Omnibox component of Google Chrome prior to version 78.0.3904.70, also affecting Google Backports_SLE and OpenSUSE distributions. This medium-severity flaw (CVSS 4.3) allows a remote attacker to perform domain spoofing through IDN homographs via a crafted domain name, requiring user interaction but having a low impact on integrity. There is no evidence of active exploitation, publicly available exploit code, or inclusion in the CISA KEV catalog, despite some community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 78.0.3904.70CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.