CVE-2018-6118 PUBLISHED

A double-eviction in the Incognito mode cache that lead to a user-after-free in cache in Google Chrome prior to 66.0.3359.139 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.

EPSS 1.03% · 77.2th percentile

Risk Scores

EPSS Score
1.03%
77.2th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSchromium-browser0, 65.0.3325.181-0ubuntu1, 65.0.3325.146-0ubuntu1
Ubuntu:16.04:LTSoxide-qt1.12.6-0ubuntu1, 0, 1.9.5-0ubuntu1
Ubuntu:16.04:LTSchromium-browser52.0.2743.116-0ubuntu0.16.04.1.1250, 51.0.2704.79-0ubuntu0.16.04.1.1242, 50.0.2661.102-0ubuntu0.16.04.1.1237

Timeline

References

Open in Interactive Console →