CVE-2019-13701: Medium severity google chrome (trace event) vulnerability
Published Nov 25, 2019
·Updated
Incorrect implementation in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Affected Software
2 affected components
Google Chrome<78.0.3904.70
openSUSE Backports=15.0-sp1
Event History
Nov 25, 2019
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
DescriptionWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
An attacker needs to get a user to interact with a crafted HTML page. The CVSS vector indicates the attack can be delivered over the network and requires no privileges, but does require user interaction.
2
What is the likely impact of successful exploitation?
A successful attack can spoof the contents shown in Chrome's Omnibox (URL bar). The stated CVSS impact is limited to integrity; no confidentiality or availability impact is listed.
3
Which Chrome versions are affected?
Google Chrome versions prior to 78.0.3904.70 are affected. Updating to 78.0.3904.70 or later addresses the vulnerable version range described.