CVE-2018-18349Incorrect Permission Assignment in Google Chrome

Severity
6.5MEDIUMNVD
EPSS
0.5%
top 33.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11
Latest updateMay 13

Description

Remote frame navigations was incorrectly permitted to local resources in Blink in Google Chrome prior to 71.0.3578.80 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a crafted Chrome Extension.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

CVEListV5google/chromeunspecified71.0.3578.80
NVDgoogle/chrome< 71.0.3578.80
Debianchromium/chromium< 71.0.3578.80-1+3

Also affects: Debian Linux 9.0

🔴Vulnerability Details

3
GHSA
GHSA-3377-vrhc-fxf7: Remote frame navigations was incorrectly permitted to local resources in Blink in Google Chrome prior to 712022-05-13
CVEList
CVE-2018-18349: Remote frame navigations was incorrectly permitted to local resources in Blink in Google Chrome prior to 712018-12-11
OSV
CVE-2018-18349: Remote frame navigations was incorrectly permitted to local resources in Blink in Google Chrome prior to 712018-12-11

📋Vendor Advisories

2
Red Hat
chromium-browser: Insufficient policy enforcement in Blink2018-12-04
Debian
CVE-2018-18349: chromium - Remote frame navigations was incorrectly permitted to local resources in Blink i...2018

💬Community

1
Bugzilla
CVE-2018-18349 chromium-browser: Insufficient policy enforcement in Blink2018-12-05
CVE-2018-18349 — Incorrect Permission Assignment | cvebase