CVE-2019-13684: Google Chrome

Medium severity, CVSS 5.3. EPSS: 0.8% chance of exploitation in the next 30 days.

Inappropriate implementation in JavaScript in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

Affected products

  • Google Chrome: before 72.0.3626.81 (fixed in 72.0.3626.81)

Published 2019-11-25. Last modified 2026-06-17.