CVE-2018-6045 describes an insufficient policy enforcement vulnerability in Google Chrome's DevTools, affecting versions prior to 64.0.3282.119, as well as Debian and Red Hat distributions. This medium-severity vulnerability (CVSS 6.5) allows a remote attacker, through user interaction with a crafted Chrome Extension, to potentially leak local user file data. While no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing is reported, there is some community discussion and media coverage indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 64.0.3282.119CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.