CVE-2018-18349: Medium severity google chrome vulnerability
An insufficient policy enforcement flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=894399
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
Other sources
Remote frame navigations was incorrectly permitted to local resources in Blink in Google Chrome prior to 71.0.3578.80 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a crafted Chrome Extension.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18349?
CVE-2018-18349 is considered a medium severity vulnerability due to insufficient policy enforcement in the Blink component of Chromium.
How do I fix CVE-2018-18349?
To fix CVE-2018-18349, update your Chromium or Google Chrome browser to the latest version available, as it contains the necessary patches.
Which versions of Chromium are affected by CVE-2018-18349?
CVE-2018-18349 affects Chromium versions prior to 71.0.3578.80.
Is CVE-2018-18349 present in Google Chrome?
Yes, CVE-2018-18349 impacts Google Chrome versions prior to 71.0.3578.80.
What happens if I don't address CVE-2018-18349?
If left unaddressed, CVE-2018-18349 could potentially allow unauthorized actions within the browser, compromising user security.