CVE-2019-13703Authentication Bypass by Spoofing in Google Chrome

Severity
4.3MEDIUMNVD
EPSS
0.3%
top 45.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 25
Latest updateMay 24

Description

Insufficient policy enforcement in the Omnibox in Google Chrome on Android prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

CVEListV5google/chromeunspecified78.0.3904.70
NVDgoogle/chrome< 78.0.3904.70
Debianchromium/chromium< 78.0.3904.87-1+3

🔴Vulnerability Details

3
GHSA
GHSA-34q3-rr2f-2gwp: Insufficient policy enforcement in the Omnibox in Google Chrome on Android prior to 782022-05-24
OSV
CVE-2019-13703: Insufficient policy enforcement in the Omnibox in Google Chrome on Android prior to 782019-11-25
CVEList
CVE-2019-13703: Insufficient policy enforcement in the Omnibox in Google Chrome on Android prior to 782019-11-25

📋Vendor Advisories

3
Red Hat
chromium-browser: URL bar spoofing2019-10-22
Chrome
Stable Channel Update for Desktop: CVE-2019-137032019-10-22
Debian
CVE-2019-13703: chromium - Insufficient policy enforcement in the Omnibox in Google Chrome on Android prior...2019

💬Community

3
Bugzilla
CVE-2019-13703 chromium-browser: URL bar spoofing2019-10-23
Bugzilla
CVE-2019-13699 CVE-2019-13700 CVE-2019-13701 CVE-2019-13702 CVE-2019-13703 CVE-2019-13704 CVE-2019-13705 CVE-2019-13706 CVE-2019-13707 CVE-2019-13708 CVE-2019-13709 CVE-2019-13710 CVE-2019-13711 CVE-22019-10-23
Bugzilla
CVE-2019-13699 CVE-2019-13700 CVE-2019-13701 CVE-2019-13702 CVE-2019-13703 CVE-2019-13704 CVE-2019-13705 CVE-2019-13706 CVE-2019-13707 CVE-2019-13708 CVE-2019-13709 CVE-2019-13710 CVE-2019-13711 CVE-22019-10-23
CVE-2019-13703 — Authentication Bypass by Spoofing | cvebase