CVE-2019-5812 describes a domain spoofing vulnerability in Google Chrome prior to version 74.0.3729.108, specifically impacting the iOS UI due to inadequate security UI. This flaw allowed a remote attacker to mislead users about the website they were visiting through a crafted HTML page, affecting various Chrome installations across Apple, Fedora, and Google platforms. Rated Medium severity with a CVSS score of 6.5, the attack requires user interaction (UI:R) but can be executed remotely (AV:N) with low complexity (AC:L), potentially leading to high integrity impacts (I:H) without affecting confidentiality or availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the CISA KEV catalog, though it garnered some community discussion and media coverage at the time of disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 74.0.3729.108CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
29CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.