CVE-2018-6066: Infoleak
Lack of CORS checking by ResourceFetcher/ResourceLoader in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Other sources
The following flaw was identified in the Chromium browser: same origin bypass via canvas.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=799477
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-6066?
CVE-2018-6066 is a vulnerability found in Google Chrome prior to version 65.0.3325.146 that allows a remote attacker to leak cross-origin data via a crafted HTML page.
How does CVE-2018-6066 work?
CVE-2018-6066 occurs due to a lack of CORS checking by ResourceFetcher/ResourceLoader in Blink, which can be exploited by a remote attacker to extract cross-origin data by using a crafted HTML page.
What is the severity of CVE-2018-6066?
The severity of CVE-2018-6066 is medium, with a severity score of 6.5.
What software is affected by CVE-2018-6066?
Google Chrome versions prior to 65.0.3325.146, as well as Redhat Linux Desktop 6.0, Redhat Linux Server 6.0, Redhat Linux Workstation 6.0, and Debian Debian Linux 9.0 are affected by CVE-2018-6066.
How can I fix CVE-2018-6066?
To fix CVE-2018-6066, make sure to update Google Chrome to version 65.0.3325.146 or later. Additionally, keep your operating system up to date with the latest security patches.