CVE-2018-6103

6 documents6 sources
Severity
6.5MEDIUM
EPSS
0.6%
top 29.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 4
Latest updateMay 13

Description

A stagnant permission prompt in Prompts in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass permission policy via a crafted HTML page.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

CVEListV5google/chromeunspecified66.0.3359.117
NVDgoogle/chrome< 66.0.3359.117
Ubuntuchromium-browser< 66.0.3359.139-0ubuntu0.16.04.3+1

Also affects: Debian Linux 8.0, 9.0

🔴Vulnerability Details

3
GHSA
GHSA-46gq-pc89-q34g: A stagnant permission prompt in Prompts in Google Chrome prior to 662022-05-13
OSV
CVE-2018-6103: A stagnant permission prompt in Prompts in Google Chrome prior to 662018-12-04
CVEList
CVE-2018-6103: A stagnant permission prompt in Prompts in Google Chrome prior to 662018-12-04

📋Vendor Advisories

1
Red Hat
chromium-browser: UI spoof in Permissions2018-04-17

💬Community

1
Bugzilla
CVE-2018-6103 chromium-browser: UI spoof in Permissions2018-04-18
CVE-2018-6103 (MEDIUM CVSS 6.5) | A stagnant permission prompt in Pro | cvebase.io