CVE-2018-20073 — Sensitive Information Exposure in Google Chrome
Severity
5.5MEDIUMNVD
EPSS
0.0%
top 92.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 27
Latest updateMay 24
Description
Use of extended attributes in downloads in Google Chrome prior to 72.0.3626.81 allowed a local attacker to read download URLs via the filesystem.
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6
Affected Packages4 packages
🔴Vulnerability Details
2📋Vendor Advisories
1Debian▶
CVE-2018-20073: chromium - Use of extended attributes in downloads in Google Chrome prior to 72.0.3626.81 a...↗2018