CVE-2018-6074: Input Validation
Failure to apply Mark-of-the-Web in Downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to bypass OS level controls via a crafted HTML page.
Other sources
The following flaw was identified in the Chromium browser: mark-of-the-web bypass.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=809759
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-6074?
CVE-2018-6074 is a vulnerability in Google Chrome prior to version 65.0.3325.146 that allows a remote attacker to bypass OS level controls via a crafted HTML page.
How severe is CVE-2018-6074?
CVE-2018-6074 has a severity value of 8.8, which is considered high.
What is the affected software for CVE-2018-6074?
The affected software includes Google Chrome versions prior to 65.0.3325.146, chromium-browser on Debian, and chromium-browser on Redhat Linux.
How can I fix CVE-2018-6074?
To fix CVE-2018-6074, update your Google Chrome to version 65.0.3325.146 or higher.
Where can I find more information about CVE-2018-6074?
You can find more information about CVE-2018-6074 on the Debian Security Tracker, the Chromium issue tracker, and the Google Chrome Releases blog.