CVE-2018-6070 describes a Content Security Policy (CSP) bypass vulnerability in Google Chrome prior to version 65.0.3325.146, specifically affecting WebUI pages within the Bink component. An attacker could exploit this by convincing a user to install a malicious Chrome Extension, thereby circumventing CSP protections. This is a medium-severity vulnerability (CVSS 6.1) requiring user interaction (UI:R) and network access (AV:N). Successful exploitation could lead to limited confidentiality and integrity impacts (C:L/I:L), as an attacker could bypass security policies. There is no evidence of active exploitation (KEV: No), and no public exploit code is available (Metasploit, Nuclei, ExploitDB: None). While there is some community discussion and media coverage, it is not indicative of widespread attention or exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 65.0.3325.146CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.