CVE-2018-6070Cross-site Scripting in Google Chrome

Severity
6.1MEDIUMNVD
EPSS
0.4%
top 40.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14
Latest updateMay 13

Description

Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages5 packages

CVEListV5google/chromeunspecified65.0.3325.146
NVDgoogle/chrome< 65.0.3325.146

Also affects: Debian Linux 9.0

🔴Vulnerability Details

3
GHSA
GHSA-c52j-5mh4-h7mf: Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 652022-05-13
CVEList
CVE-2018-6070: Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 652018-11-14
OSV
CVE-2018-6070: Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 652018-11-14

📋Vendor Advisories

1
Red Hat
chromium-browser: csp bypass through extensions2018-03-06

💬Community

3
Bugzilla
CVE-2018-6057 CVE-2018-6060 CVE-2018-6061 CVE-2018-6062 CVE-2018-6063 CVE-2018-6064 CVE-2018-6065 CVE-2018-6066 CVE-2018-6067 CVE-2018-6069 CVE-2018-6070 CVE-2018-6071 CVE-2018-6072 CVE-2018-6073 CVE-2018-03-07
Bugzilla
CVE-2018-6070 chromium-browser: csp bypass through extensions2018-03-07
Bugzilla
CVE-2018-6057 CVE-2018-6060 CVE-2018-6061 CVE-2018-6062 CVE-2018-6063 CVE-2018-6064 CVE-2018-6065 CVE-2018-6066 CVE-2018-6067 CVE-2018-6069 CVE-2018-6070 CVE-2018-6071 CVE-2018-6072 CVE-2018-6073 CVE-2018-03-07
CVE-2018-6070 — Cross-site Scripting in Google Chrome | cvebase