CVE-2018-6076: XSS
An incorrect handling of url fragment identifiers flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=758523
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Other sources
Insufficient encoding of URL fragment identifiers in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform a DOM based XSS attack via a crafted HTML page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6076?
The severity of CVE-2018-6076 is medium, with a severity value of 6.1.
How does CVE-2018-6076 affect Google Chrome?
CVE-2018-6076 affects Google Chrome versions prior to 65.0.3325.146.
How can a remote attacker exploit CVE-2018-6076?
A remote attacker can exploit CVE-2018-6076 by performing a DOM based XSS attack via a crafted HTML page.
What is the remedy for CVE-2018-6076?
There is no specific remedy mentioned for CVE-2018-6076.
Where can I find more information about CVE-2018-6076?
You can find more information about CVE-2018-6076 at the following references: [1](https://security-tracker.debian.org/tracker/CVE-2018-6076), [2](https://code.google.com/p/chromium/issues/detail?id=758523), [3](https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html)