CVE-2019-5781 is a medium-severity vulnerability affecting Google Chrome prior to version 72.0.3626.81, as well as Debian, Fedora, and Red Hat distributions. It involves incorrect handling of confusable characters in the Omnibox, allowing a remote attacker to spoof the URL bar's contents through a crafted domain name. The attack requires user interaction (UI:R) and has a high impact on integrity (I:H), but no impact on confidentiality or availability. There is no evidence of active exploitation, and no public exploit code is available, though it has received some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 72.0.3626.81CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.