CVE-2018-6078: Input Validation
An url spoof flaw was found in the OmniBox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=793628
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Other sources
Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6078?
CVE-2018-6078 has been classified as a high severity vulnerability due to the potential for URL spoofing.
How do I fix CVE-2018-6078?
To mitigate CVE-2018-6078, users should update to the latest version of Chromium or Google Chrome, specifically beyond version 65.0.3325.146.
Which software is affected by CVE-2018-6078?
CVE-2018-6078 affects Chromium Browser up to version 65.0.3325.146 and Google Chrome versions prior to the available patch.
What type of vulnerability is CVE-2018-6078?
CVE-2018-6078 is a URL spoofing vulnerability that can deceive users by misrepresenting the destination of links.
Is there a workaround for CVE-2018-6078?
There are no known workarounds for CVE-2018-6078; updating to a secure version is the recommended solution.