CVE-2018-20073 describes a vulnerability in Google Chrome prior to version 72.0.3626.81, where a local attacker could read download URLs through the filesystem due to improper use of extended attributes. This medium-severity flaw (CVSS 5.5) has a low attack complexity and requires local access, potentially leading to high confidentiality impact by exposing sensitive download information. While not listed on the KEV catalog and lacking public exploit intelligence (Metasploit, Nuclei, ExploitDB), it has garnered minimal community discussion and limited media coverage, suggesting it is not widely exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 72.0.3626.81CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.