CVE-2018-16078 describes an unsafe handling of credit card details within Google Chrome's Autofill feature, affecting versions prior to 69.0.3497.81, as well as various Google and Red Hat enterprise Linux distributions. This vulnerability, rated Medium severity (CVSS 6.5), allows a remote attacker to obtain potentially sensitive information, specifically credit card details, from process memory through a crafted HTML page, requiring user interaction. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 69.0.3497.81CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.