First published: Wed Mar 07 2018(Updated: )
Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to access privileged APIs via a crafted HTML page.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/chromium-browser | ||
redhat/chromium-browser | <65.0.3325.146 | 65.0.3325.146 |
Google Chrome (Trace Event) | <65.0.3325.146 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
Debian | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6083 has a medium severity level due to its potential to allow unauthorized access to privileged APIs.
CVE-2018-6083 affects all versions of Google Chrome prior to 65.0.3325.146.
To mitigate CVE-2018-6083, update Google Chrome or Chromium to version 65.0.3325.146 or later.
Yes, CVE-2018-6083 affects Debian systems running versions of Chromium prior to 65.0.3325.146.
CVE-2018-6083 impacts applications that utilize affected versions of Google Chrome and Chromium browsers.