CVE-2018-6125 describes an insufficient policy enforcement vulnerability in Google Chrome on Windows, specifically versions prior to 67.0.3396.62. This flaw allowed a remote attacker to potentially obtain sensitive information by enticing a user to visit a specially crafted HTML page. With a CVSS score of 6.5 (Medium), the vulnerability has a network attack vector, low attack complexity, and high confidentiality impact, requiring user interaction. There is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog. Community discussion and media coverage are minimal, with only one mention and one article identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 67.0.3396.62CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.