CVE-2018-6063: High severity google chrome vulnerability
Incorrect use of mojo::WrapSharedMemoryHandle in Mojo in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page.
Other sources
The following flaw was identified in the Chromium browser: incorrect permissions on shared memory.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=792900
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6063?
The severity of CVE-2018-6063 is critical due to the potential for a remote attacker to exploit the vulnerability for arbitrary code execution.
How do I fix CVE-2018-6063?
To fix CVE-2018-6063, update Google Chrome or the affected Chromium browser to version 65.0.3325.146 or later.
Which versions of Chromium are affected by CVE-2018-6063?
CVE-2018-6063 affects Chromium versions prior to 65.0.3325.146.
Can CVE-2018-6063 lead to data breaches?
Yes, CVE-2018-6063 could potentially allow an attacker to conduct out of bounds memory writes, leading to data breaches.
Who is vulnerable to CVE-2018-6063?
Users of the affected versions of Google Chrome and Chromium, particularly those who visit malicious HTML pages, are vulnerable to CVE-2018-6063.