Insufficient policy enforcement in Catalog Service in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially run arbitrary code outside sandbox via a crafted HTML page.
References
Link | Resource |
---|---|
https://crbug.com/791003 | Exploit Issue Tracking Vendor Advisory |
https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html | Vendor Advisory |
http://www.securityfocus.com/bid/105516 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2018-09-25 07:29
Updated : 2018-11-20 08:33
NVD link : CVE-2018-6055
Mitre link : CVE-2018-6055
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
- chrome