CVE-2018-18344: Medium severity google chrome vulnerability
An inappropriate implementation flaw was found in the Extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=866426
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
Other sources
Inappropriate allowance of the setDownloadBehavior devtools protocol feature in Extensions in Google Chrome prior to 71.0.3578.80 allowed a remote attacker with control of an installed extension to access files on the local file system via a crafted Chrome Extension.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18344?
CVE-2018-18344 has been classified as a medium severity vulnerability.
How do I fix CVE-2018-18344?
To fix CVE-2018-18344, update your Chromium browser to the latest version provided by your operating system's package manager.
What is the impact of CVE-2018-18344 on users?
CVE-2018-18344 may allow attackers to manipulate the browser's extensions, leading to potential security risks for users.
Which software versions are affected by CVE-2018-18344?
CVE-2018-18344 affects specific versions of Chromium and Google Chrome, particularly those below version 71.0.3578.80.
Is there a workaround for CVE-2018-18344?
Currently, the best workaround for CVE-2018-18344 is to disable extensions until the browser is updated.