CVE-2018-6169
published 2019-01-09CVE-2018-6169: Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to trigger installation of an…
PriorityP429medium6.5CVSS 3.0
AVNACLPRNUIRSUCNIHAN
EPSS
1.35%
68.6th percentile
Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to trigger installation of an unwanted extension via a crafted HTML page.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| chrome | < 68.0.3440.75 | 68.0.3440.75 | |
| chrome | >= unspecified < 68.0.3440.75 | 68.0.3440.75 | |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m8w6-9c44-28r8: Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68
ghsa_unreviewed·2022-05-14
CVE-2018-6169 [MEDIUM] CWE-20 GHSA-m8w6-9c44-28r8: Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68
Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to trigger installation of an unwanted extension via a crafted HTML page.
OSV
CVE-2018-6169: Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68
osv·2019-01-09·CVSS 6.5
CVE-2018-6169 [MEDIUM] CVE-2018-6169: Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68
Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to trigger installation of an unwanted extension via a crafted HTML page.
Red Hat
chromium-browser: Permissions bypass in extension installation
vendor_redhat·2018-07-24·CVSS 6.5
CVE-2018-6169 [MEDIUM] chromium-browser: Permissions bypass in extension installation
chromium-browser: Permissions bypass in extension installation
Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to trigger installation of an unwanted extension via a crafted HTML page.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/104887https://access.redhat.com/errata/RHSA-2018:2282https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.htmlhttps://crbug.com/394518https://security.gentoo.org/glsa/201808-01https://www.debian.org/security/2018/dsa-4256http://www.securityfocus.com/bid/104887https://access.redhat.com/errata/RHSA-2018:2282https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.htmlhttps://crbug.com/394518https://security.gentoo.org/glsa/201808-01https://www.debian.org/security/2018/dsa-4256
2019-01-09
Published