CVE-2018-18350 PUBLISHED

Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass content security policy via a crafted HTML page.

EPSS 0.63% · 70.0th percentile

Risk Scores

EPSS Score
0.63%
70.0th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSchromium-browser0, 61.0.3163.100-0ubuntu1.1378, 62.0.3202.62-0ubuntu0.17.10.1380
Ubuntu:16.04:LTSchromium-browser60.0.3112.78-0ubuntu0.16.04.1293, 60.0.3112.113-0ubuntu0.16.04.1298, 61.0.3163.79-0ubuntu0.16.04.1300

Timeline

References

Open in Interactive Console →