CVE-2018-6129 describes an out-of-bounds array access vulnerability in WebRTC within Google Chrome versions prior to 67.0.3396.62. This flaw allowed a remote attacker to potentially perform out-of-bounds memory access by enticing a user to visit a specially crafted HTML page. It carries a CVSS score of 6.5 (Medium), indicating a network-based attack with low complexity, requiring user interaction, and primarily leading to high availability impact. While not listed in CISA's KEV catalog, an ExploitDB entry (EDB-44863) exists, and the vulnerability has garnered moderate community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 67.0.3396.62CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.