CVE-2018-18347

Severity
8.8HIGH
EPSS
1.6%
top 18.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11
Latest updateMay 14

Description

Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to trick a user into executing javascript in an arbitrary origin via a crafted HTML page.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages6 packages

CVEListV5google/chromeunspecified71.0.3578.80
NVDgoogle/chrome< 71.0.3578.80
Debianchromium< 71.0.3578.80-1+3

Also affects: Debian Linux 9.0

🔴Vulnerability Details

3
GHSA
GHSA-8fhg-mg99-7m3j: Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 712022-05-14
CVEList
CVE-2018-18347: Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 712018-12-11
OSV
CVE-2018-18347: Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 712018-12-11

📋Vendor Advisories

2
Red Hat
chromium-browser: Inappropriate implementation in Navigation2018-12-04
Debian
CVE-2018-18347: chromium - Incorrect handling of failed navigations with invalid URLs in Navigation in Goog...2018

💬Community

1
Bugzilla
CVE-2018-18347 chromium-browser: Inappropriate implementation in Navigation2018-12-05