CVE-2018-18350: Medium severity google chrome vulnerability
An insufficient policy enforcement flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=799747
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
Other sources
Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18350?
CVE-2018-18350 is classified as a high severity vulnerability due to insufficient policy enforcement in the Blink component of the Chromium browser.
How do I fix CVE-2018-18350?
To fix CVE-2018-18350, you should update your Chromium browser to version 71.0.3578.80 or higher for affected versions.
Which versions of Chromium are affected by CVE-2018-18350?
CVE-2018-18350 affects Chromium browsers prior to version 71.0.3578.80, along with specific Debian and Red Hat releases.
What component is impacted by CVE-2018-18350?
CVE-2018-18350 impacts the Blink component of the Chromium browser.
Is CVE-2018-18350 a browser vulnerability?
Yes, CVE-2018-18350 is a security vulnerability specific to the Chromium browser and its derivatives.