CVE-2018-6132 is a medium-severity vulnerability affecting Google Chrome versions prior to 67.0.3396.62, where uninitialized data in WebRTC could allow a remote attacker to obtain potentially sensitive information from process memory by tricking a user into opening a crafted video file. The attack requires user interaction (UI:R) and has a low impact on confidentiality (C:L), with no impact on integrity or availability. There is no evidence of active exploitation, nor are there publicly available exploit modules or proof-of-concept code. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 67.0.3396.62CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.