Google · Google Chrome · CVE-2018-6076
**Name of the Vulnerable Software and Affected Versions**
Google Chrome versions prior to 65.0.3325.146
Opera versions prior to 65.0.3325.146
**Description**
The issue is related to insufficient encoding of URL fragment identifiers in Blink, which allowed a remote attacker to perform a DOM based XSS attack via a crafted HTML page.
**Recommendations**
For Google Chrome versions prior to 65.0.3325.146, update to version 65.0.3325.146 or later.
For Opera versions prior to 65.0.3325.146, update to version 65.0.3325.146 or later.