CVE-2018-6081Cross-site Scripting in Google Chrome

Severity
6.1MEDIUMNVD
EPSS
0.4%
top 40.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14
Latest updateMay 14

Description

XSS vulnerabilities in Interstitials in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension or open Developer Console to inject arbitrary scripts or HTML via a crafted HTML page.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages5 packages

CVEListV5google/chromeunspecified65.0.3325.146
NVDgoogle/chrome< 65.0.3325.146

Also affects: Debian Linux 9.0

🔴Vulnerability Details

3
GHSA
GHSA-jhhp-5gch-wqvm: XSS vulnerabilities in Interstitials in Google Chrome prior to 652022-05-14
OSV
CVE-2018-6081: XSS vulnerabilities in Interstitials in Google Chrome prior to 652018-11-14
CVEList
CVE-2018-6081: XSS vulnerabilities in Interstitials in Google Chrome prior to 652018-11-14

📋Vendor Advisories

1
Red Hat
chromium-browser: xss in interstitials2018-03-06

💬Community

2
Bugzilla
qt5-qtwebengine: 16 security vulnerabilities2018-03-24
Bugzilla
CVE-2018-6081 chromium-browser: xss in interstitials2018-03-07
CVE-2018-6081 — Cross-site Scripting in Google Chrome | cvebase