CVE-2018-20065 describes a vulnerability in Google Chrome versions prior to 71.0.3578.80, where a crafted PDF file could exploit PDFium's handling of URI actions to initiate potentially unsafe navigations without user interaction. This vulnerability carries a high CVSS score of 8.8, indicating a critical risk due to its network attack vector, low attack complexity, and high potential impact on confidentiality, integrity, and availability. While no active exploitation, Metasploit modules, or Nuclei templates are publicly available, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 71.0.3578.80CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.