CVE-2018-6095: Infoleak
Inappropriate dismissal of file picker on keyboard events in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to read local files via a crafted HTML page.
Other sources
The following flaw was identified in the Chromium browser: Lack of meaningful user interaction requirement before file upload.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=637098
External References:
https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
— Red Hat
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-6085
- CVE-2018-6086
- CVE-2018-6087
- CVE-2018-6088
- CVE-2018-6089
- CVE-2018-6090
- CVE-2018-6091
- CVE-2018-6092
- CVE-2018-6093
- CVE-2018-6152
- CVE-2018-6094
- CVE-2018-6150
- CVE-2018-6096
- CVE-2018-6097
- CVE-2018-6151
- CVE-2018-6098
- CVE-2018-6099
- CVE-2018-6100
- CVE-2018-6101
- CVE-2018-6102
- CVE-2018-6103
- CVE-2018-6104
- CVE-2018-6105
- CVE-2018-6106
- CVE-2018-6107
- CVE-2018-6108
- CVE-2018-6109
- CVE-2018-6110
- CVE-2018-6111
- CVE-2018-6112
- CVE-2018-6113
- CVE-2018-6114
- CVE-2018-6115
- CVE-2018-6116
- CVE-2018-6117
- CVE-2018-6084
Frequently Asked Questions
What is the severity of CVE-2018-6095?
The severity of CVE-2018-6095 is medium, with a severity value of 6.5.
How can a remote attacker exploit CVE-2018-6095?
A remote attacker can exploit CVE-2018-6095 by crafting a malicious HTML page that allows them to read local files.
What is the affected software for CVE-2018-6095?
The affected software for CVE-2018-6095 includes Google Chrome prior to version 66.0.3359.117, Chromium Browser (package) on Debian and Redhat Linux Desktop, Server, and Workstation (version 6.0), and Debian Linux (versions 8.0 and 9.0).
How do I fix CVE-2018-6095 in Google Chrome?
To fix CVE-2018-6095 in Google Chrome, you need to update to version 66.0.3359.117 or later.
Where can I find more information about CVE-2018-6095?
You can find more information about CVE-2018-6095 on the Debian Security Tracker, Google Chromium issues page, and the Google Chrome Stable Channel Updates blog post.