CVE-2018-6178
published 2019-01-09CVE-2018-6178: Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious…
PriorityP419medium4.3CVSS 3.0
AVNACLPRNUIRSUCNILAN
EPSS
0.92%
56.8th percentile
Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to Hide Chrome Security UI via a crafted Chrome Extension.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| chrome | < 68.0.3440.75 | 68.0.3440.75 | |
| chrome | >= unspecified < 68.0.3440.75 | 68.0.3440.75 | |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vx2p-vj7w-cwgh: Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68
ghsa_unreviewed·2022-05-13
CVE-2018-6178 [MEDIUM] CWE-1021 GHSA-vx2p-vj7w-cwgh: Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68
Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to Hide Chrome Security UI via a crafted Chrome Extension.
OSV
CVE-2018-6178: Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68
osv·2019-01-09·CVSS 4.3
CVE-2018-6178 [MEDIUM] CVE-2018-6178: Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68
Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to Hide Chrome Security UI via a crafted Chrome Extension.
Red Hat
chromium-browser: UI spoof in Extensions
vendor_redhat·2018-07-24·CVSS 4.3
CVE-2018-6178 [MEDIUM] chromium-browser: UI spoof in Extensions
chromium-browser: UI spoof in Extensions
Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to Hide Chrome Security UI via a crafted Chrome Extension.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/104887https://access.redhat.com/errata/RHSA-2018:2282https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.htmlhttps://crbug.com/823194https://security.gentoo.org/glsa/201808-01https://www.debian.org/security/2018/dsa-4256http://www.securityfocus.com/bid/104887https://access.redhat.com/errata/RHSA-2018:2282https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.htmlhttps://crbug.com/823194https://security.gentoo.org/glsa/201808-01https://www.debian.org/security/2018/dsa-4256
2019-01-09
Published