CVE-2018-18351Improper Input Validation in Google Chrome

Severity
6.5MEDIUMNVD
EPSS
0.7%
top 27.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11
Latest updateMay 14

Description

Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass SameSite cookie policy via a crafted HTML page.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

CVEListV5google/chromeunspecified71.0.3578.80
NVDgoogle/chrome< 71.0.3578.80
Debianchromium/chromium< 71.0.3578.80-1+3

Also affects: Debian Linux 9.0

🔴Vulnerability Details

3
GHSA
GHSA-j8q6-cppq-xgq5: Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 712022-05-14
OSV
CVE-2018-18351: Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 712018-12-11
CVEList
CVE-2018-18351: Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 712018-12-11

📋Vendor Advisories

2
Red Hat
chromium-browser: Insufficient policy enforcement in Navigation2018-12-04
Debian
CVE-2018-18351: chromium - Lack of proper validation of ancestor frames site when sending lax cookies in Na...2018

💬Community

1
Bugzilla
CVE-2018-18351 chromium-browser: Insufficient policy enforcement in Navigation2018-12-05
CVE-2018-18351 — Improper Input Validation in Google | cvebase