CVE-2019-13757: Medium severity google chrome vulnerability
An incorrect security ui flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=884693
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Other sources
Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-13757.
What is the affected software?
The affected software includes Google Chrome prior to version 79.0.3945.79, chromium-browser, Google Chrome, Debian Debian Linux, Fedoraproject Fedora, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux For Scientific Computing, Redhat Enterprise Linux Server, and Redhat Enterprise Linux Workstation.
What is the severity of CVE-2019-13757?
The severity of CVE-2019-13757 is medium with a severity value of 4.3.
How can a remote attacker exploit CVE-2019-13757?
A remote attacker can exploit CVE-2019-13757 by performing domain spoofing via IDN homographs using a crafted domain name.
How can I fix CVE-2019-13757?
To fix CVE-2019-13757, update Google Chrome to version 79.0.3945.79 or later.