CVE-2019-13747 is a high-severity vulnerability affecting Google Chrome on Android prior to version 79.0.3945.79, as well as various Linux distributions like Debian and Fedora. It stems from uninitialized data in the rendering engine, allowing a remote attacker to potentially achieve heap corruption through a specially crafted HTML page. The attack requires user interaction (UI:R) but has low attack complexity (AC:L) and can lead to high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H). While the vulnerability has a high CVSS score of 8.8 and a FAUCET Risk Score of 73/100, there is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage beyond its initial disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 79.0.3945.79CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.