CVE-2018-18356 describes an integer overflow in Skia's path handling within Google Chrome versions prior to 71.0.3578.80, leading to a use-after-free vulnerability. This flaw allows a remote attacker to potentially exploit heap corruption by enticing a user to visit a crafted HTML page, affecting various distributions including Canonical, Debian, Google, OpenSUSE, and Red Hat. With a CVSS score of 8.8 (High), the vulnerability is network-exploitable with low attack complexity, requiring user interaction, and could result in high impacts to confidentiality, integrity, and availability. While the vulnerability has garnered some community discussion and media coverage, there is no evidence of active exploitation, nor are there publicly available exploit modules or KEV catalog listings.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 71.0.3578.80CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.