CVE-2018-16068: Input Validation
An out of bounds write flaw was found in the Mojo component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=877182
External References:
https://chromereleases.googleblog.com/2018/09/stable-channel-update-for-desktop.html
Other sources
Missing validation in Mojo in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-16068?
CVE-2018-16068 has a medium severity rating as it allows a potential sandbox escape in Google Chrome.
How do I fix CVE-2018-16068?
To mitigate CVE-2018-16068, upgrade to Google Chrome or Chromium version 69.0.3497.81 or later.
Which versions of Chrome are affected by CVE-2018-16068?
CVE-2018-16068 affects Google Chrome versions prior to 69.0.3497.81.
What kind of attack does CVE-2018-16068 enable?
CVE-2018-16068 could potentially allow remote attackers to perform a sandbox escape via a crafted HTML page.
Is CVE-2018-16068 applicable to any specific operating systems?
CVE-2018-16068 is applicable to multiple operating systems where affected versions of Google Chrome or Chromium are installed.