CVE-2018-18351 — Improper Input Validation in Google Chrome
Severity
6.5MEDIUMNVD
EPSS
0.7%
top 27.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 11
Latest updateMay 14
Description
Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass SameSite cookie policy via a crafted HTML page.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6
Affected Packages6 packages
Also affects: Debian Linux 9.0
🔴Vulnerability Details
3GHSA▶
GHSA-j8q6-cppq-xgq5: Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71↗2022-05-14
OSV▶
CVE-2018-18351: Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71↗2018-12-11
CVEList▶
CVE-2018-18351: Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71↗2018-12-11