CVE-2018-20067 describes a user interface spoofing vulnerability in Google Chrome versions prior to 71.0.3578.80. A remote attacker could craft an HTML page to confuse users about the origin of the current page by incorrectly canceling a browser-initiated back navigation. This vulnerability has a CVSS score of 4.3 (MEDIUM), indicating a low impact on integrity and requiring user interaction, but no confidentiality or availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, though it has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 71.0.3578.80CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.