PT-2018-3265 · Google+3 · Google Chrome+3

Published

2018-07-24

·

Updated

2024-06-15

·

CVE-2018-6171

CVSS v2.0

6.1

Medium

VectorAV:A/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 68.0.3440.75
Description The issue is related to a use after free error in the WebBluetooth component of Google Chrome, which can be exploited by a remote attacker. This exploitation can lead to the installation of a malicious Chrome extension, resulting in unauthorized access to sensitive information.
Recommendations For versions prior to 68.0.3440.75, update to version 68.0.3440.75 or later to resolve the issue. As a temporary workaround, consider restricting the installation of new extensions to minimize the risk of exploitation.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2278
BDU:2019-04461
CVE-2018-6171
DSA-4256-1
MGASA-2018-0343
OPENSUSE-SU-2018_2134-1
OPENSUSE-SU-2024:10681-1
OPENSUSE-SU-2024:12948-1
RHSA-2018:2282
RHSA-2018_2282

Affected Products

Alt Linux
Google Chrome
Red Hat
Suse