CVE-2018-6075: Infoleak
Incorrect handling of specified filenames in file downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page and user interaction.
Other sources
The following flaw was identified in the Chromium browser: overly permissive cross origin downloads.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=608669
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-6075?
CVE-2018-6075 is a vulnerability that allowed a remote attacker to leak cross-origin data via a crafted HTML page and user interaction in Google Chrome prior to 65.0.3325.146.
How does CVE-2018-6075 affect Google Chrome?
CVE-2018-6075 affects Google Chrome versions prior to 65.0.3325.146.
What is the severity of CVE-2018-6075?
CVE-2018-6075 has a severity rating of 6.5 (medium).
What is the remedy for CVE-2018-6075?
There are no known remedies for CVE-2018-6075 at this time.
Where can I find more information about CVE-2018-6075?
You can find more information about CVE-2018-6075 at the following references: [Link 1](https://security-tracker.debian.org/tracker/CVE-2018-6075), [Link 2](https://code.google.com/p/chromium/issues/detail?id=608669), [Link 3](https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html).