First published: Mon Nov 25 2019(Updated: )
Insufficient data validation in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <78.0.3904.70 | |
openSUSE Backports | =15.0-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13718 is rated as high severity due to the potential for domain spoofing.
To fix CVE-2019-13718, update Google Chrome to version 78.0.3904.70 or later.
CVE-2019-13718 affects Google Chrome prior to version 78.0.3904.70 and openSUSE Backports version 15.0-sp1.
CVE-2019-13718 allows attackers to execute domain spoofing attacks, potentially deceiving users into visiting malicious sites.
You can determine if you're vulnerable to CVE-2019-13718 by checking if you are using an outdated version of Google Chrome prior to 78.0.3904.70.