CVE-2018-18357: Medium severity google chrome vulnerability
An insufficient policy enforcement flaw was found in the URL Formatter component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=895207
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
Other sources
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18357?
CVE-2018-18357 is classified as a medium severity vulnerability due to insufficient policy enforcement in the Chromium browser.
How do I fix CVE-2018-18357?
To fix CVE-2018-18357, update the Chromium browser to one of the patched versions listed in the vulnerability details.
What versions of Chromium are affected by CVE-2018-18357?
CVE-2018-18357 affects various versions of the Chromium browser prior to the updates specified in the vendor advisories.
Which operating systems are vulnerable to CVE-2018-18357?
CVE-2018-18357 impacts multiple operating systems, including Debian and Red Hat Enterprise Linux, that utilize affected versions of Chromium.
Is CVE-2018-18357 exploitable in the wild?
There is currently no public evidence that CVE-2018-18357 is actively being exploited in the wild.