CVE-2018-18347
published 2018-12-11CVE-2018-18347: Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to trick a user into…
PriorityP342high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.39%
69.4th percentile
Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to trick a user into executing javascript in an arbitrary origin via a crafted HTML page.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| debian | chromium | < chromium 71.0.3578.80-1 (bookworm) | chromium 71.0.3578.80-1 (bookworm) |
| debian | debian_linux | — | — |
| chrome | < 71.0.3578.80 | 71.0.3578.80 | |
| chrome | >= unspecified < 71.0.3578.80 | 71.0.3578.80 | |
| redhat | linux_desktop | — | — |
| redhat | linux_server | — | — |
| redhat | linux_workstation | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: Inappropriate implementation in Navigation
vendor_redhat·2018-12-04·CVSS 8.8
CVE-2018-18347 [HIGH] chromium-browser: Inappropriate implementation in Navigation
chromium-browser: Inappropriate implementation in Navigation
Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to trick a user into executing javascript in an arbitrary origin via a crafted HTML page.
Debian
CVE-2018-18347: chromium - Incorrect handling of failed navigations with invalid URLs in Navigation in Goog...
vendor_debian·2018·CVSS 8.8
CVE-2018-18347 [HIGH] CVE-2018-18347: chromium - Incorrect handling of failed navigations with invalid URLs in Navigation in Goog...
Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to trick a user into executing javascript in an arbitrary origin via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 71.0.3578.80-1)
bullseye: resolved (fixed in 71.0.3578.80-1)
forky: resolved (fixed in 71.0.3578.80-1)
sid: resolved (fixed in 71.0.3578.80-1)
trixie: resolved (fixed in 71.0.3578.80-1)
GHSA
GHSA-8fhg-mg99-7m3j: Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71
ghsa_unreviewed·2022-05-14
CVE-2018-18347 [HIGH] CWE-20 GHSA-8fhg-mg99-7m3j: Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71
Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to trick a user into executing javascript in an arbitrary origin via a crafted HTML page.
OSV
CVE-2018-18347: Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71
osv·2018-12-11·CVSS 8.8
CVE-2018-18347 [HIGH] CVE-2018-18347: Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71
Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to trick a user into executing javascript in an arbitrary origin via a crafted HTML page.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/106084https://access.redhat.com/errata/RHSA-2018:3803https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.htmlhttps://crbug.com/850824https://security.gentoo.org/glsa/201908-18https://www.debian.org/security/2018/dsa-4352http://www.securityfocus.com/bid/106084https://access.redhat.com/errata/RHSA-2018:3803https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.htmlhttps://crbug.com/850824https://security.gentoo.org/glsa/201908-18https://www.debian.org/security/2018/dsa-4352
2018-12-11
Published