CVE-2018-6127: Use After Free
An use after free flaw was found in the indexedDB component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=842990
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop58.html
Other sources
Early free of object in use in IndexDB in Google Chrome prior to 67.0.3396.62 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6127?
CVE-2018-6127 is considered a high severity vulnerability due to its potential to allow an attacker to execute arbitrary code in the context of the user.
How do I fix CVE-2018-6127?
To fix CVE-2018-6127, users should update Chromium to version 67.0.3396.62 or later.
What systems are affected by CVE-2018-6127?
CVE-2018-6127 affects various versions of Chromium and Google Chrome browsers, specifically those prior to version 67.0.3396.62.
Can CVE-2018-6127 be exploited remotely?
Yes, CVE-2018-6127 can be exploited remotely through crafted web content that triggers the use-after-free flaw.
What are the potential impacts of CVE-2018-6127?
The potential impacts of CVE-2018-6127 include arbitrary code execution, allowing attackers to take control of affected systems.