CVE-2018-16074Improper Authorization in Google Chrome

Severity
6.5MEDIUMNVD
EPSS
0.2%
top 63.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 27
Latest updateMay 24

Description

Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass site isolation via a crafted HTML page.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5google/chromeunspecified69.0.3497.81
NVDgoogle/chrome< 69.0.3497.81

🔴Vulnerability Details

2
GHSA
GHSA-xj43-gc98-hg3f: Insufficient policy enforcement in site isolation in Google Chrome prior to 692022-05-24
OSV
CVE-2018-16074: Insufficient policy enforcement in site isolation in Google Chrome prior to 692019-06-27

📋Vendor Advisories

1
Red Hat
chromium-browser: Site Isolation bypass using Blob URLS2018-09-04

💬Community

3
Bugzilla
CVE-2018-16074 chromium-browser: Site Isolation bypass using Blob URLS2018-09-05
Bugzilla
CVE-2018-16065 CVE-2018-16066 CVE-2018-16067 CVE-2018-16068 CVE-2018-16069 CVE-2018-16070 CVE-2018-16071 CVE-2018-16072 CVE-2018-16073 CVE-2018-16074 CVE-2018-16075 CVE-2018-16076 CVE-2018-16077 CVE-22018-09-05
Bugzilla
CVE-2018-16065 CVE-2018-16066 CVE-2018-16067 CVE-2018-16068 CVE-2018-16069 CVE-2018-16070 CVE-2018-16071 CVE-2018-16072 CVE-2018-16073 CVE-2018-16074 CVE-2018-16075 CVE-2018-16076 CVE-2018-16077 CVE-22018-09-05