CVE-2018-18348: Medium severity google chrome vulnerability
An inappropriate implementation flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=881659
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
Other sources
Incorrect handling of bidirectional domain names with RTL characters in Omnibox in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18348?
CVE-2018-18348 has a high severity rating due to its inappropriate implementation flaw in the Omnibox component of Chromium.
How do I fix CVE-2018-18348?
To fix CVE-2018-18348, users should update their Chromium browser to version 71.0.3578.80 or later.
Which versions of Chromium are affected by CVE-2018-18348?
CVE-2018-18348 affects Chromium versions up to 71.0.3578.80.
Is CVE-2018-18348 present in Google Chrome?
Yes, CVE-2018-18348 is present in Google Chrome versions up to 71.0.3578.80.
What components are involved in CVE-2018-18348?
CVE-2018-18348 specifically involves an inappropriate implementation flaw in the Omnibox component of the Chromium browser.