CVE-2018-18336 describes a heap corruption vulnerability in PDFium, a component of Google Chrome prior to version 71.0.3578.80, which could be triggered by a specially crafted PDF file. This high-severity vulnerability (CVSS 8.8) allows a remote attacker to achieve high impact on confidentiality, integrity, and availability with low attack complexity, requiring user interaction. While there is no evidence of active exploitation (not in KEV or Hot List), no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion, the vulnerability has received some media coverage. It primarily affects Google Chrome on Debian and Red Hat systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 71.0.3578.80CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:linux_desktop:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:linux_server:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:linux_workstation:6.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.