CVE-2018-6147
published 2019-01-09CVE-2018-6147: Lack of secure text entry mode in Browser UI in Google Chrome on Mac prior to 67.0.3396.62 allowed a local attacker to obtain potentially sensitive information…
PriorityP421medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.40%
32.8th percentile
Lack of secure text entry mode in Browser UI in Google Chrome on Mac prior to 67.0.3396.62 allowed a local attacker to obtain potentially sensitive information from process memory via a local process.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| chrome | < 67.0.3396.62 | 67.0.3396.62 | |
| chrome | >= unspecified < 67.0.3396.62 | 67.0.3396.62 | |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wq23-fxhr-wjq3: Lack of secure text entry mode in Browser UI in Google Chrome on Mac prior to 67
ghsa_unreviewed·2022-05-14
CVE-2018-6147 [MEDIUM] CWE-200 GHSA-wq23-fxhr-wjq3: Lack of secure text entry mode in Browser UI in Google Chrome on Mac prior to 67
Lack of secure text entry mode in Browser UI in Google Chrome on Mac prior to 67.0.3396.62 allowed a local attacker to obtain potentially sensitive information from process memory via a local process.
OSV
CVE-2018-6147: Lack of secure text entry mode in Browser UI in Google Chrome on Mac prior to 67
osv·2019-01-09·CVSS 5.5
CVE-2018-6147 [MEDIUM] CVE-2018-6147: Lack of secure text entry mode in Browser UI in Google Chrome on Mac prior to 67
Lack of secure text entry mode in Browser UI in Google Chrome on Mac prior to 67.0.3396.62 allowed a local attacker to obtain potentially sensitive information from process memory via a local process.
Red Hat
chromium-browser: Password fields not taking advantage of OS protections in Views
vendor_redhat·2018-05-29·CVSS 5.5
CVE-2018-6147 [MEDIUM] chromium-browser: Password fields not taking advantage of OS protections in Views
chromium-browser: Password fields not taking advantage of OS protections in Views
Lack of secure text entry mode in Browser UI in Google Chrome on Mac prior to 67.0.3396.62 allowed a local attacker to obtain potentially sensitive information from process memory via a local process.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/104309http://www.securitytracker.com/id/1041014https://access.redhat.com/errata/RHSA-2018:1815https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.htmlhttps://crbug.com/818133https://www.debian.org/security/2018/dsa-4237http://www.securityfocus.com/bid/104309http://www.securitytracker.com/id/1041014https://access.redhat.com/errata/RHSA-2018:1815https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.htmlhttps://crbug.com/818133https://www.debian.org/security/2018/dsa-4237
2019-01-09
Published