CVE-2018-6057: High severity google chrome vulnerability
Lack of special casing of Android ashmem in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process to bypass inter-process read only guarantees via a crafted HTML page.
Other sources
The following flaw was identified in the Chromium browser: incorrect permissions on shared memory.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=789959
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6057?
CVE-2018-6057 has been classified with a high severity due to its potential to allow remote attackers to bypass inter-process read only guarantees.
How do I fix CVE-2018-6057?
To fix CVE-2018-6057, update Google Chrome or Chromium to version 65.0.3325.146 or later.
Which versions of Google Chrome are affected by CVE-2018-6057?
CVE-2018-6057 affects Google Chrome versions prior to 65.0.3325.146.
What environments are impacted by CVE-2018-6057?
CVE-2018-6057 impacts various environments including Debian GNU/Linux 9.0 and Red Hat Enterprise Linux 6.0.
Who is the attacker in CVE-2018-6057?
In CVE-2018-6057, the attacker is a remote individual who can compromise the renderer process through a crafted HTML page.