Vulnerability · NVD
CVE-2018-6152
CVE-2018-6152, critical severity (CVSS 9.6): 2 tracked apps concerned, all fixed or indeterminable on their current version.
- Severity (CVSS)
- 9.6
- Exploitation
- 1.3 %
- Tracked apps
- 2
- Still exposed
- 0
NVD scale
EPSS, predicted over 30 days
The implementation of the Page.downloadBehavior backend unconditionally marked downloaded files as safe, regardless of file type in Google Chrome prior to 66.0.3359.117 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page and user interaction.
Show raw CVSS vector
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
-
Affected <66.0.3359.106 Fixed in 66.0.3359.106 Latest tracked - undetermined
-
NVD references 5 distinct products for this CVE : only those tracked by Scout (mobile and desktop catalog apps) are listed above. Libraries, servers and out-of-scope products do not appear here. Full list on NVD ↗
Vulnerable CPE configurations (2)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
|
chrome All platforms (wildcard)
|
All platforms (wildcard) | <66.0.3359.106 | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | |
|
chrome All platforms (wildcard)
|
All platforms (wildcard) | <66.0.3359.106 | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |