Information disclosure in Google Chrome - CVE-2018-6150

 

Information disclosure in Google Chrome - CVE-2018-6150

Published: July 27, 2018


Vulnerability identifier: #VU14031
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-6150
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The weakness exists due to unspecified flaw. A remote attacker can trick the victim into visiting a specially crafted website and gain access to arbitrary data.

Affected software

Google Chrome
Debian Linux
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Fedora
chromium

How to mitigate CVE-2018-6150

Update to version 68.0.3440.75.

Google Chrome - update to 68.0.3440.75
chromium - addressed in versions 68.0.3440.106-3.el7, 68.0.3440.106-3.fc27, 68.0.3440.106-3.fc28

External References

Related Security Bulletins