CVE-2018-6083: High severity google chrome vulnerability
Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to access privileged APIs via a crafted HTML page.
Other sources
The following flaw was identified in the Chromium browser: incorrect processing of appmanifests.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=771709
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6083?
CVE-2018-6083 has a medium severity level due to its potential to allow unauthorized access to privileged APIs.
What versions of Google Chrome are affected by CVE-2018-6083?
CVE-2018-6083 affects all versions of Google Chrome prior to 65.0.3325.146.
How can I mitigate CVE-2018-6083?
To mitigate CVE-2018-6083, update Google Chrome or Chromium to version 65.0.3325.146 or later.
Does CVE-2018-6083 affect Debian systems?
Yes, CVE-2018-6083 affects Debian systems running versions of Chromium prior to 65.0.3325.146.
What applications are impacted by CVE-2018-6083?
CVE-2018-6083 impacts applications that utilize affected versions of Google Chrome and Chromium browsers.