CVE-2018-18358: Input Validation
An insufficient policy enforcement flaw was found in the Proxy component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=899126
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
Other sources
Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18358?
CVE-2018-18358 has been rated as a medium severity vulnerability due to the insufficient policy enforcement in the Chromium browser.
How do I fix CVE-2018-18358?
To fix CVE-2018-18358, users should update their Chromium browsers to the latest versions specified in the remediation list.
Which versions of Chromium are affected by CVE-2018-18358?
CVE-2018-18358 affects Chromium versions prior to 71.0.3578.80 and specific versions in the Debian and Red Hat environments.
Does CVE-2018-18358 affect Google Chrome?
Yes, CVE-2018-18358 affects Google Chrome versions up to and including 71.0.3578.80.
Is there a workaround for CVE-2018-18358?
No specific workaround for CVE-2018-18358 is available, so updating to the latest version is recommended.