CVE-2018-18354Improper Input Validation in Google Chrome

Severity
8.8HIGHNVD
EPSS
1.6%
top 18.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11
Latest updateMay 14

Description

Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71.0.3578.80 allowed a remote attacker to launch external programs via a crafted HTML page.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages6 packages

CVEListV5google/chromeunspecified71.0.3578.80
NVDgoogle/chrome< 71.0.3578.80
Debianchromium/chromium< 71.0.3578.80-1+3

Also affects: Debian Linux 9.0

🔴Vulnerability Details

3
GHSA
GHSA-g5c2-53mv-qgrh: Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 712022-05-14
CVEList
CVE-2018-18354: Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 712018-12-11
OSV
CVE-2018-18354: Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 712018-12-11

📋Vendor Advisories

2
Red Hat
chromium-browser: Insufficient data validation in Shell Integration2018-12-04
Debian
CVE-2018-18354: chromium - Insufficient validate of external protocols in Shell Integration in Google Chrom...2018

💬Community

1
Bugzilla
CVE-2018-18354 chromium-browser: Insufficient data validation in Shell Integration2018-12-05
CVE-2018-18354 — Improper Input Validation in Google | cvebase