CVE-2018-6070: XSS
Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.
Other sources
The following flaw was identified in the Chromium browser: csp bypass through extensions.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=668645
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6070?
CVE-2018-6070 is classified as a moderate severity vulnerability affecting Google Chrome and Chromium browsers.
How do I fix CVE-2018-6070?
To mitigate CVE-2018-6070, users should upgrade to Google Chrome version 65.0.3325.146 or later.
What does CVE-2018-6070 exploit?
CVE-2018-6070 exploits a lack of Content Security Policy enforcement in WebUI pages of Chromium-based browsers.
Who is affected by CVE-2018-6070?
Users of Google Chrome versions before 65.0.3325.146 and certain versions of the Chromium browser are affected by CVE-2018-6070.
Can CVE-2018-6070 be exploited remotely?
Yes, CVE-2018-6070 can be exploited remotely if an attacker convinces a victim to install a malicious Chrome extension.