CVE-2018-6126 describes a precision error in Skia, a 2D graphics library, within Google Chrome versions prior to 67.0.3396.62, impacting products like Debian and Red Hat. This vulnerability allows a remote attacker to achieve an out-of-bounds memory write by enticing a user to visit a specially crafted HTML page. With a CVSS score of 8.8 (High), it poses a significant risk, enabling high confidentiality, integrity, and availability impacts with low attack complexity. While not listed in CISA's KEV catalog, an ExploitDB entry (EDB-45098) detailing a heap overflow in SkScan::FillPath exists, and it has garnered notable community discussion and media coverage, indicating awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 67.0.3396.62CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.