CVE-2018-6140: Input Validation
A restrictions bypass flaw was found in the the debugger extension API component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=798222
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop58.html
Other sources
Allowing the chrome.debugger API to attach to Web UI pages in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6140?
CVE-2018-6140 has a medium severity rating due to the potential for a restrictions bypass in the Chromium browser's debugger extension API.
How do I fix CVE-2018-6140?
To fix CVE-2018-6140, upgrade to Chromium version 67.0.3396.62 or later.
What software is affected by CVE-2018-6140?
CVE-2018-6140 affects Chromium browser versions below 67.0.3396.62, as well as Google Chrome and certain versions of Debian and Red Hat Linux.
What is the nature of CVE-2018-6140?
CVE-2018-6140 is a vulnerability that allows for a bypass of restrictions in the debugger extension API of the Chromium browser.
Is CVE-2018-6140 exploitable in the wild?
There is no public information indicating that CVE-2018-6140 is actively exploited in the wild, but it poses a risk if left unpatched.