CVE-2018-6098: URL spoof in Omnibox
An url spoof flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=798892
External References:
https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
Other sources
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-6085
- CVE-2018-6086
- CVE-2018-6087
- CVE-2018-6088
- CVE-2018-6089
- CVE-2018-6090
- CVE-2018-6091
- CVE-2018-6092
- CVE-2018-6093
- CVE-2018-6152
- CVE-2018-6094
- CVE-2018-6095
- CVE-2018-6150
- CVE-2018-6096
- CVE-2018-6097
- CVE-2018-6151
- CVE-2018-6099
- CVE-2018-6100
- CVE-2018-6101
- CVE-2018-6102
- CVE-2018-6103
- CVE-2018-6104
- CVE-2018-6105
- CVE-2018-6106
- CVE-2018-6107
- CVE-2018-6108
- CVE-2018-6109
- CVE-2018-6110
- CVE-2018-6111
- CVE-2018-6112
- CVE-2018-6113
- CVE-2018-6114
- CVE-2018-6115
- CVE-2018-6116
- CVE-2018-6117
- CVE-2018-6084
Frequently Asked Questions
What is the vulnerability ID of the vulnerability?
The vulnerability ID of the vulnerability is CVE-2018-6098.
What is the title of the vulnerability?
The title of the vulnerability is 'Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117'.
What is the severity of CVE-2018-6098?
The severity of CVE-2018-6098 is medium with a severity value of 6.5.
What software versions are affected by CVE-2018-6098?
Versions prior to 66.0.3359.117 of Google Chrome are affected by CVE-2018-6098.
How can I fix CVE-2018-6098?
To fix CVE-2018-6098, it is recommended to update Google Chrome to version 66.0.3359.117 or later.