PT-2018-3267 · Google+3 · Google Chrome+3
Khalil Zhani
·
Publicado
2018-07-24
·
Atualizado
2024-06-15
·
CVE-2018-6173
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 68.0.3440.75
Description
The issue is related to the incorrect handling of confusable characters in the URL Formatter, allowing a remote attacker to perform domain spoofing via IDN homographs using a crafted domain name. This can lead to the spoofing of the Omnibox (URL) component.
Recommendations
For versions prior to 68.0.3440.75, update to version 68.0.3440.75 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially vulnerable domains to minimize the risk of exploitation.
Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Google Chrome
Red Hat
Suse