CVE-2018-18354 — Improper Input Validation in Google Chrome
Severity
8.8HIGHNVD
EPSS
1.6%
top 18.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 11
Latest updateMay 14
Description
Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71.0.3578.80 allowed a remote attacker to launch external programs via a crafted HTML page.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages6 packages
Also affects: Debian Linux 9.0
🔴Vulnerability Details
3GHSA▶
GHSA-g5c2-53mv-qgrh: Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71↗2022-05-14
CVEList▶
CVE-2018-18354: Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71↗2018-12-11
OSV▶
CVE-2018-18354: Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71↗2018-12-11
📋Vendor Advisories
2💬Community
1Bugzilla
▶