CVE-2018-18347
Severity
8.8HIGH
EPSS
1.6%
top 18.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 11
Latest updateMay 14
Description
Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to trick a user into executing javascript in an arbitrary origin via a crafted HTML page.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages6 packages
Also affects: Debian Linux 9.0
🔴Vulnerability Details
3GHSA▶
GHSA-8fhg-mg99-7m3j: Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71↗2022-05-14
CVEList▶
CVE-2018-18347: Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71↗2018-12-11
OSV▶
CVE-2018-18347: Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71↗2018-12-11