CVE-2018-20065: Input Validation
Published Jan 9, 2019
·Updated
Handling of URI action in PDFium in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to initiate potentially unsafe navigations without a user gesture via a crafted PDF file.
Affected Software
1 affected component
Google Chrome<71.0.3578.80
Event History
Jan 9, 2019
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-20065?
CVE-2018-20065 is classified as a high-severity vulnerability.
2
How do I fix CVE-2018-20065?
To fix CVE-2018-20065, upgrade Google Chrome to version 71.0.3578.80 or later.
3
What does CVE-2018-20065 exploit?
CVE-2018-20065 exploits the handling of URI actions in PDFium within Google Chrome.
4
What is the impact of CVE-2018-20065?
The impact of CVE-2018-20065 is that it allows remote attackers to initiate unsafe navigations without user interaction.
5
Which versions of Google Chrome are affected by CVE-2018-20065?
Google Chrome versions prior to 71.0.3578.80 are affected by CVE-2018-20065.