Security restrictions bypass in Google Chrome - CVE-2018-6091
Published: April 19, 2018 / Updated: June 11, 2021
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions.
The vulnerability exists due to the incorrect handling of plug-ins by Service Worker. A remote unauthenticated attacker can trick the victim into visiting a specially crafted website, bypass same origin policy restrictions and gain unauthorized access to the system.
Affected software
Gentoo Linux
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Fedora
SUSE Linux
chromium
How to mitigate CVE-2018-6091
chromium - addressed in versions 66.0.3359.181-2.fc27, 66.0.3359.181-2.fc28, 66.0.3359.181-3.el7, 67.0.3396.79-1.el7
External References
Related Security Bulletins
- Multiple vulnerabilities in Google Chrome
- OpenSUSE Linux update for chromium
- Gentoo update for Chromium, Google Chrome
- Red Hat update for Google Chrome
- Debian update for chromium-browser
- OpenSUSE Linux update for Chromium
- SUSE Linux update for chromium
- Fedora EPEL 7 update for chromium
- Fedora 27 update for chromium
- Fedora 28 update for chromium
- Fedora EPEL 7 update for chromium