Security restrictions bypass in Google Chrome - CVE-2018-17472
Published: October 23, 2018
Vulnerability identifier: #VU15482
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-17472
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The weakness exists due to iframe sandbox escape on iOS. A remote attacker can trick the victim into visiting a specially crafted website and bypass security restrictions to conduct further attacks.
The weakness exists due to iframe sandbox escape on iOS. A remote attacker can trick the victim into visiting a specially crafted website and bypass security restrictions to conduct further attacks.
Affected software
Google Chrome
Opensuse
Fedora
chromium
Opensuse
Fedora
chromium
How to mitigate CVE-2018-17472
Update to version 70.0.3538.67.
Google Chrome - update to 70.0.3538.67
chromium - addressed in versions 70.0.3538.77-4.fc27, 70.0.3538.77-4.fc28, 70.0.3538.77-4.fc29, 70.0.3538.110-1.fc28
chromium - addressed in versions 70.0.3538.77-4.fc27, 70.0.3538.77-4.fc28, 70.0.3538.77-4.fc29, 70.0.3538.110-1.fc28