CVE-2019-13674
published 2019-11-25CVE-2019-13674: IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain…
PriorityP418medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.67%
48.2th percentile
IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| debian | chromium | < chromium 78.0.3904.87-1 (bookworm) | chromium 78.0.3904.87-1 (bookworm) |
| chrome | < 77.0.3865.75 | 77.0.3865.75 | |
| chrome | >= unspecified < 77.0.3865.75 | 77.0.3865.75 | |
| chrome_desktop | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-79rx-rpqc-99fp: IDN spoofing in Omnibox in Google Chrome prior to 77
ghsa_unreviewed·2022-05-24
CVE-2019-13674 [MEDIUM] GHSA-79rx-rpqc-99fp: IDN spoofing in Omnibox in Google Chrome prior to 77
IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Project0
Déjà vu-lnerability - Project Zero
project_zero·2021-02-01
CVE-2014-9665 Déjà vu-lnerability - Project Zero
A Year in Review of 0-days Exploited In-The-Wild in 2020
Posted by Maddie Stone, Project Zero
2020 was a year full of 0-day exploits. Many of the Internet’s most popular browsers had their moment in the spotlight. Memory corruption is still the name of the game and how the vast majority of detected 0-days are getting in. While we tried new methods of 0-day detection with modest success, 2020 showed us that there is still a long way to go in detecting these 0-day exploits in-the-wild. But what may be the most notable fact is that 25% of the 0-days detected in 2020 are closely related to previously publicly disclosed vulnerabilities. In other words, 1 out of every 4 detected 0-day exploits could potentially have been avoided if a more thorough investigation and patching effort were explor
OSV
CVE-2019-13674: IDN spoofing in Omnibox in Google Chrome prior to 77
osv·2019-11-25·CVSS 4.3
CVE-2019-13674 [MEDIUM] CVE-2019-13674: IDN spoofing in Omnibox in Google Chrome prior to 77
IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Chrome
Stable Channel Update for Desktop: CVE-2019-13673
vendor_chrome·2019-09-10·CVSS 7.4
CVE-2019-13673 [MEDIUM] Stable Channel Update for Desktop: CVE-2019-13673
Stable Channel Update for Desktop
CVE-2019-13673: Cross-origin information leak using devtools. Reported by David Erceg on 2019-08-26
[$500][ 896533 ] Low CVE-2019-13674: IDN spoofing
Reported by Khalil Zhani on 2018-10-18
Severity: medium
Red Hat
chromium-browser: IDN spoofing
vendor_redhat·2019-09-10·CVSS 4.3
CVE-2019-13674 [MEDIUM] chromium-browser: IDN spoofing
chromium-browser: IDN spoofing
IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Debian
CVE-2019-13674: chromium - IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote ...
vendor_debian·2019·CVSS 4.3
CVE-2019-13674 [MEDIUM] CVE-2019-13674: chromium - IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote ...
IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved (fixed in 78.0.3904.87-1)
No detection rules found.
No public exploits indexed.
2019-11-25
Published