CVE-2018-6066 PUBLISHED

Lack of CORS checking by ResourceFetcher/ResourceLoader in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

EPSS 14.41% · 94.4th percentile

Risk Scores

EPSS Score
14.41%
94.4th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSoxide-qt0, 1.21.5-0ubuntu0.16.04.1, 1.20.4-0ubuntu0.16.04.1
Ubuntu:16.04:LTSchromium-browser58.0.3029.96-0ubuntu0.16.04.1279, 0, 45.0.2454.101-0ubuntu1.1201
Ubuntu:14.04:LTSchromium-browser29.0.1547.65-0ubuntu2, 49.0.2623.87-0ubuntu0.14.04.1.1112, 48.0.2564.116-0ubuntu0.14.04.1.1111

Timeline

References

Open in Interactive Console →