CVE-2018-18355: Medium severity google chrome vulnerability
An insufficient policy enforcement flaw was found in the URL Formatter component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=896717
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
Other sources
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18355?
CVE-2018-18355 is classified as a medium severity vulnerability.
How do I fix CVE-2018-18355?
To fix CVE-2018-18355, update your Chromium or Chrome browser to the latest version available.
Which versions are affected by CVE-2018-18355?
CVE-2018-18355 affects Chrome versions prior to 71.0.3578.80 and specific Chromium versions prior to the latest mentioned in the remediation list.
What type of vulnerability is CVE-2018-18355?
CVE-2018-18355 is an insufficient policy enforcement flaw in the URL Formatter component.
Is CVE-2018-18355 present in open source browsers?
Yes, CVE-2018-18355 affects open source browsers derived from Chromium, including specific packages in Debian and Red Hat.