Spoofing attack in Google Chrome - CVE-2018-6133

 

Spoofing attack in Google Chrome - CVE-2018-6133

Published: May 31, 2018 / Updated: June 6, 2021


Vulnerability identifier: #VU13095
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-6133
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to an error in OmniBox. A remote attacker can trick the victim into visiting a specially crafted website and conduct URL spoofing attack.


Affected software

Google Chrome
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Fedora
SUSE Linux
Opensuse
openSUSE Leap
chromium

How to mitigate CVE-2018-6133

Update to version 67.0.3396.62.

Google Chrome - update to 67.0.3396.62
chromium - addressed in versions 67.0.3396.79-1.el7, 67.0.3396.79-1.fc27, 67.0.3396.79-1.fc28

External References

Related Security Bulletins