CVE-2018-6083
published 2018-11-14CVE-2018-6083: Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to access…
PriorityP343high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.55%
72.2th percentile
Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to access privileged APIs via a crafted HTML page.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| chrome | < 65.0.3325.146 | 65.0.3325.146 | |
| chrome | >= unspecified < 65.0.3325.146 | 65.0.3325.146 | |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jhfw-3fvm-pf8m: Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in Google Chrome prior to 65
ghsa_unreviewed·2022-05-13
CVE-2018-6083 [HIGH] GHSA-jhfw-3fvm-pf8m: Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in Google Chrome prior to 65
Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to access privileged APIs via a crafted HTML page.
OSV
CVE-2018-6083: Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in Google Chrome prior to 65
osv·2018-11-14·CVSS 8.8
CVE-2018-6083 [HIGH] CVE-2018-6083: Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in Google Chrome prior to 65
Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to access privileged APIs via a crafted HTML page.
Red Hat
chromium-browser: incorrect processing of appmanifests
vendor_redhat·2018-03-06·CVSS 8.8
CVE-2018-6083 [HIGH] chromium-browser: incorrect processing of appmanifests
chromium-browser: incorrect processing of appmanifests
Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to access privileged APIs via a crafted HTML page.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/103297https://access.redhat.com/errata/RHSA-2018:0484https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.htmlhttps://crbug.com/771709https://www.debian.org/security/2018/dsa-4182http://www.securityfocus.com/bid/103297https://access.redhat.com/errata/RHSA-2018:0484https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.htmlhttps://crbug.com/771709https://www.debian.org/security/2018/dsa-4182
2018-11-14
Published