CVE-2018-6112
published 2019-01-09CVE-2018-6112: Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass navigation…
PriorityP419medium4.3CVSS 3.0
AVNACLPRNUIRSUCLINAN
EPSS
1.59%
73.2th percentile
Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| chrome | < 66.0.3359.117 | 66.0.3359.117 | |
| chrome | >= unspecified < 66.0.3359.117 | 66.0.3359.117 | |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2r72-mfwr-5645: Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66
ghsa_unreviewed·2022-05-13
CVE-2018-6112 [MEDIUM] CWE-706 GHSA-2r72-mfwr-5645: Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66
Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
OSV
CVE-2018-6112: Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66
osv·2019-01-09·CVSS 4.3
CVE-2018-6112 [MEDIUM] CVE-2018-6112: Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66
Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Red Hat
chromium-browser: Incorrect URL handling in DevTools
vendor_redhat·2018-04-17·CVSS 4.3
CVE-2018-6112 [MEDIUM] chromium-browser: Incorrect URL handling in DevTools
chromium-browser: Incorrect URL handling in DevTools
Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/103917https://access.redhat.com/errata/RHSA-2018:1195https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.htmlhttps://crbug.com/798096https://security.gentoo.org/glsa/201804-22https://www.debian.org/security/2018/dsa-4182http://www.securityfocus.com/bid/103917https://access.redhat.com/errata/RHSA-2018:1195https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.htmlhttps://crbug.com/798096https://security.gentoo.org/glsa/201804-22https://www.debian.org/security/2018/dsa-4182
2019-01-09
Published