CVE-2018-16077 describes an object lifecycle issue within Google Chrome's Blink rendering engine, affecting versions prior to 69.0.3497.81. This vulnerability allows a remote attacker to bypass Content Security Policy (CSP) protections through a specially crafted HTML page. Rated as MEDIUM severity (CVSS 6.5), it requires user interaction (UI:R) but can be exploited over the network (AV:N) with low attack complexity (AC:L), leading to high integrity impacts (I:H) without confidentiality or availability concerns. There is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, and it has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 69.0.3497.81CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.