CVE-2018-18351: Input Validation
An insufficient policy enforcement flaw was found in the Navigation component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=833847
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
Other sources
Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass SameSite cookie policy via a crafted HTML page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18351?
CVE-2018-18351 has been classified as a medium severity vulnerability.
How do I fix CVE-2018-18351?
To fix CVE-2018-18351, update your Chromium browser to the fixed versions released by the respective distributions.
Which versions of Chromium are affected by CVE-2018-18351?
CVE-2018-18351 affects multiple versions of Chromium, including those prior to 71.0.3578.80.
Is Google Chrome affected by CVE-2018-18351?
Yes, Google Chrome is affected by CVE-2018-18351 for versions prior to 71.0.3578.80.
What component is impacted by CVE-2018-18351?
CVE-2018-18351 impacts the Navigation component of the Chromium browser.