CVE-2018-6179
published 2019-01-09CVE-2018-6179: Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced…
PriorityP431medium6.5CVSS 3.0
AVNACLPRNUIRSUCHINAN
EPSS
1.18%
64.5th percentile
Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a crafted Chrome Extension.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| chrome | < 68.0.3440.75 | 68.0.3440.75 | |
| chrome | >= unspecified < 68.0.3440.75 | 68.0.3440.75 | |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-83j2-pmf7-p2m2: Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chrome prior to 68
ghsa_unreviewed·2022-05-14
CVE-2018-6179 [MEDIUM] CWE-200 GHSA-83j2-pmf7-p2m2: Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chrome prior to 68
Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a crafted Chrome Extension.
OSV
CVE-2018-6179: Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chrome prior to 68
osv·2019-01-09·CVSS 6.5
CVE-2018-6179 [MEDIUM] CVE-2018-6179: Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chrome prior to 68
Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a crafted Chrome Extension.
Red Hat
chromium-browser: Local file information leak in Extensions
vendor_redhat·2018-07-24·CVSS 6.5
CVE-2018-6179 [MEDIUM] chromium-browser: Local file information leak in Extensions
chromium-browser: Local file information leak in Extensions
Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a crafted Chrome Extension.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/104887https://access.redhat.com/errata/RHSA-2018:2282https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.htmlhttps://crbug.com/816685https://security.gentoo.org/glsa/201808-01https://www.debian.org/security/2018/dsa-4256http://www.securityfocus.com/bid/104887https://access.redhat.com/errata/RHSA-2018:2282https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.htmlhttps://crbug.com/816685https://security.gentoo.org/glsa/201808-01https://www.debian.org/security/2018/dsa-4256
2019-01-09
Published