CVE-2018-6113
published 2019-01-09CVE-2018-6113: Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66.0.3359.117 allowed a remote attacker to perform domain…
PriorityP428medium6.5CVSS 3.0
AVNACLPRNUIRSUCNIHAN
EPSS
1.45%
70.7th percentile
Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| chrome | < 66.0.3359.117 | 66.0.3359.117 | |
| chrome | >= unspecified < 66.0.3359.117 | 66.0.3359.117 | |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2h73-vgw2-r579: Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66
ghsa_unreviewed·2022-05-13
CVE-2018-6113 [MEDIUM] CWE-20 GHSA-2h73-vgw2-r579: Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66
Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
OSV
CVE-2018-6113: Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66
osv·2019-01-09·CVSS 6.5
CVE-2018-6113 [MEDIUM] CVE-2018-6113: Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66
Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Red Hat
chromium-browser: URL spoof in Navigation
vendor_redhat·2018-04-17·CVSS 6.5
CVE-2018-6113 [MEDIUM] chromium-browser: URL spoof in Navigation
chromium-browser: URL spoof in Navigation
Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/103917https://access.redhat.com/errata/RHSA-2018:1195https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.htmlhttps://crbug.com/805900https://security.gentoo.org/glsa/201804-22https://www.debian.org/security/2018/dsa-4182http://www.securityfocus.com/bid/103917https://access.redhat.com/errata/RHSA-2018:1195https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.htmlhttps://crbug.com/805900https://security.gentoo.org/glsa/201804-22https://www.debian.org/security/2018/dsa-4182
2019-01-09
Published