CVE-2018-6090 is a high-severity integer overflow vulnerability in Skia, a graphics engine used by Google Chrome prior to version 66.0.3359.117, affecting Debian, Google, and Red Hat products. This flaw allowed a remote attacker to execute arbitrary code within the browser's sandbox by enticing a user to visit a specially crafted HTML page. With a CVSS score of 8.8 (HIGH), it presents a significant risk due to its network-based attack vector, low attack complexity, and high potential for confidentiality, integrity, and availability impacts. While there is no known active exploitation (KEV) or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered notable community discussion and media coverage, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 66.0.3359.117CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:linux_desktop:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:linux_server:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:linux_workstation:6.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.