Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2018-6084Improper Input Validation in Google Chrome

Severity
7.8HIGHNVD
EPSS
0.1%
top 68.52%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJan 9
Latest updateMay 13

Description

Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local attacker to execute arbitrary code via an executable file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

CVEListV5google/chromeunspecified66.0.3359.117
NVDgoogle/chrome< 66.0.3359.117

Also affects: Debian Linux 9.0

🔴Vulnerability Details

2
GHSA
GHSA-9q37-frcq-v33g: Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 662022-05-13
CVEList
CVE-2018-6084: Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 662019-01-09

💥Exploits & PoCs

1
Exploit-DB
Google Software Updater macOS - Unsafe use of Distributed Objects Privilege Escalation2018-03-20

📋Vendor Advisories

1
Red Hat
chromium-browser: Incorrect use of Distributed Objects in Google Software Updater on MacOS2018-04-17

💬Community

1
Bugzilla
CVE-2018-6084 chromium-browser: Incorrect use of Distributed Objects in Google Software Updater on MacOS2018-04-18
CVE-2018-6084 — Improper Input Validation in Google | cvebase