Security restrictions bypass in Google Chrome - CVE-2018-6114
Published: April 19, 2018 / Updated: June 11, 2021
Vulnerability identifier: #VU11986
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-6114
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions.
The vulnerability exists due to unspecified flaw. A remote unauthenticated attacker can trick the victim into visiting a specially crafted website, bypass CSP and gain unauthorized access to the system.
Affected software
Google Chrome
Gentoo Linux
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Fedora
SUSE Linux
chromium
Gentoo Linux
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Fedora
SUSE Linux
chromium
How to mitigate CVE-2018-6114
Update to version 66.0.3359.117.
Google Chrome - update to 66.0.3359.117
chromium - addressed in versions 66.0.3359.181-2.fc27, 66.0.3359.181-2.fc28, 66.0.3359.181-3.el7, 67.0.3396.79-1.el7
chromium - addressed in versions 66.0.3359.181-2.fc27, 66.0.3359.181-2.fc28, 66.0.3359.181-3.el7, 67.0.3396.79-1.el7
External References
Related Security Bulletins
- Multiple vulnerabilities in Google Chrome
- OpenSUSE Linux update for chromium
- Gentoo update for Chromium, Google Chrome
- Red Hat update for Google Chrome
- Debian update for chromium-browser
- OpenSUSE Linux update for Chromium
- SUSE Linux update for chromium
- Fedora EPEL 7 update for chromium
- Fedora 27 update for chromium
- Fedora 28 update for chromium
- Fedora EPEL 7 update for chromium