Security restrictions bypass in Google Chrome - CVE-2018-6115
Published: April 19, 2018 / Updated: June 11, 2021
Vulnerability identifier: #VU11988
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-6115
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions.
The vulnerability exists due to unspecified flaw. A remote unauthenticated attacker can trick the victim into visiting a specially crafted website, bypass SmartScreen in downloads and gain unauthorized access to the system.
Affected software
Google Chrome
Gentoo Linux
Fedora
SUSE Linux
chromium
Gentoo Linux
Fedora
SUSE Linux
chromium
How to mitigate CVE-2018-6115
Update to version 66.0.3359.117.
Google Chrome - update to 66.0.3359.117
chromium - addressed in versions 66.0.3359.181-2.fc27, 66.0.3359.181-2.fc28, 66.0.3359.181-3.el7, 67.0.3396.79-1.el7
chromium - addressed in versions 66.0.3359.181-2.fc27, 66.0.3359.181-2.fc28, 66.0.3359.181-3.el7, 67.0.3396.79-1.el7
External References
Related Security Bulletins
- Multiple vulnerabilities in Google Chrome
- OpenSUSE Linux update for chromium
- Gentoo update for Chromium, Google Chrome
- OpenSUSE Linux update for Chromium
- SUSE Linux update for chromium
- Fedora EPEL 7 update for chromium
- Fedora 27 update for chromium
- Fedora 28 update for chromium
- Fedora EPEL 7 update for chromium