CVE-2019-13739: Medium severity google chrome vulnerability
An incorrect security ui flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=824715
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Other sources
Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-13739?
The severity of CVE-2019-13739 is medium with a severity score of 6.5.
How does CVE-2019-13739 exploit work?
CVE-2019-13739 exploits an insufficient policy enforcement in the Omnibox in Google Chrome prior to version 79.0.3945.79 that allows a remote attacker to perform domain spoofing via IDN homographs using a crafted domain name.
Which software versions are affected by CVE-2019-13739?
Google Chrome prior to version 79.0.3945.79, Chromium prior to version 90.0.4430.212-1 (Debian 10), and Chromium prior to version 116.0.5845.180-1 (Debian 11 and 12) are affected by CVE-2019-13739.
How can I fix CVE-2019-13739?
To fix CVE-2019-13739, users should update their Google Chrome or Chromium browser to version 79.0.3945.79 or higher.
Where can I find more information about CVE-2019-13739?
You can find more information about CVE-2019-13739 on the Debian Security Tracker, Chromium issue tracker, and the Google Chrome Releases blog.