CVE-2018-6077: Infoleak
Displacement map filters being applied to cross-origin images in Blink SVG rendering in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Other sources
The following flaw was identified in the Chromium browser: timing attack using svg filters.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=778506
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6077?
CVE-2018-6077 has been classified as a high-severity vulnerability.
How do I fix CVE-2018-6077?
To fix CVE-2018-6077, update your browser to version 65.0.3325.146 or later.
What software is affected by CVE-2018-6077?
CVE-2018-6077 affects Google Chrome versions prior to 65.0.3325.146 and various versions of the Chromium browser.
What does CVE-2018-6077 exploit?
CVE-2018-6077 exploits a vulnerability in how displacement map filters are applied to cross-origin images in Blink SVG rendering.
What can attackers achieve with CVE-2018-6077?
An attacker can leverage CVE-2018-6077 to leak cross-origin data via a crafted HTML page.