CVE-2018-6109: Infoleak
readAsText() can indefinitely read the file picked by the user, rather than only once at the time the file is picked in File API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to access data on the user file system without explicit consent via a crafted HTML page.
Other sources
The following flaw was identified in the Chromium browser: Incorrect handling of files by FileAPI.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=710190
External References:
https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
— Red Hat
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-6085
- CVE-2018-6086
- CVE-2018-6087
- CVE-2018-6088
- CVE-2018-6089
- CVE-2018-6090
- CVE-2018-6091
- CVE-2018-6092
- CVE-2018-6093
- CVE-2018-6152
- CVE-2018-6094
- CVE-2018-6095
- CVE-2018-6150
- CVE-2018-6096
- CVE-2018-6097
- CVE-2018-6151
- CVE-2018-6098
- CVE-2018-6099
- CVE-2018-6100
- CVE-2018-6101
- CVE-2018-6102
- CVE-2018-6103
- CVE-2018-6104
- CVE-2018-6105
- CVE-2018-6106
- CVE-2018-6107
- CVE-2018-6108
- CVE-2018-6110
- CVE-2018-6111
- CVE-2018-6112
- CVE-2018-6113
- CVE-2018-6114
- CVE-2018-6115
- CVE-2018-6116
- CVE-2018-6117
- CVE-2018-6084
Frequently Asked Questions
What is the severity of CVE-2018-6109?
CVE-2018-6109 is classified as a high-severity vulnerability due to its potential to allow unauthorized access to the user's file system.
How do I fix CVE-2018-6109?
To mitigate CVE-2018-6109, upgrade Google Chrome or Chromium to version 66.0.3359.117 or later.
Which versions of Google Chrome are affected by CVE-2018-6109?
Google Chrome versions prior to 66.0.3359.117 are affected by CVE-2018-6109.
Is CVE-2018-6109 specific to any operating system?
CVE-2018-6109 affects Google Chrome across multiple operating systems, including Windows, macOS, and Linux.
What types of attacks can exploit CVE-2018-6109?
CVE-2018-6109 can be exploited via crafted HTML pages to gain unauthorized access to user files.