CVE-2018-6138Improper Input Validation in Google Chrome

Severity
8.1HIGHNVD
EPSS
0.1%
top 79.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 27
Latest updateMay 24

Description

Insufficient policy enforcement in Extensions API in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages2 packages

CVEListV5google/chromeunspecified67.0.3396.62
NVDgoogle/chrome< 67.0.3396.62

🔴Vulnerability Details

2
GHSA
GHSA-c7xr-m3c7-ggf3: Insufficient policy enforcement in Extensions API in Google Chrome prior to 672022-05-24
OSV
CVE-2018-6138: Insufficient policy enforcement in Extensions API in Google Chrome prior to 672019-06-27

📋Vendor Advisories

1
Red Hat
chromium-browser: Overly permissive policy in Extensions2018-05-29

💬Community

3
Bugzilla
CVE-2018-6138 chromium-browser: Overly permissive policy in Extensions2018-05-30
Bugzilla
CVE-2018-6123 CVE-2018-6124 CVE-2018-6125 CVE-2018-6126 CVE-2018-6127 CVE-2018-6129 CVE-2018-6130 CVE-2018-6131 CVE-2018-6132 CVE-2018-6133 CVE-2018-6134 CVE-2018-6135 CVE-2018-6136 CVE-2018-6137 CVE-2018-05-30
Bugzilla
CVE-2018-6123 CVE-2018-6124 CVE-2018-6125 CVE-2018-6126 CVE-2018-6127 CVE-2018-6129 CVE-2018-6130 CVE-2018-6131 CVE-2018-6132 CVE-2018-6133 CVE-2018-6134 CVE-2018-6135 CVE-2018-6136 CVE-2018-6137 CVE-2018-05-30