CVE-2018-18353: Medium severity google chrome vulnerability
An inappropriate implementation flaw was found in the Network Authentication component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=884179
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
Other sources
Failure to dismiss http auth dialogs on navigation in Network Authentication in Google Chrome on Android prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of an auto dialog via a crafted HTML page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18353?
CVE-2018-18353 is classified as a medium-severity vulnerability due to its potential impact on user security.
How do I fix CVE-2018-18353?
To fix CVE-2018-18353, update your Chromium browser to version 90.0.4430.212 or later for Debian systems, or to version 71.0.3578.80 or later for Red Hat systems.
Which software is affected by CVE-2018-18353?
CVE-2018-18353 affects multiple versions of the Chromium browser as well as Google Chrome versions up to 71.0.3578.80.
What causes the issue in CVE-2018-18353?
CVE-2018-18353 is caused by an inappropriate implementation flaw in the Network Authentication component of the Chromium browser.
Is there a workaround for CVE-2018-18353?
There are no known workarounds for CVE-2018-18353, so updating to a fixed version is recommended.