CVE-2018-6134 describes an information leak vulnerability in Google Chrome versions prior to 67.0.3396.62, specifically within its Blink rendering engine. A remote attacker could exploit this flaw by crafting a malicious HTML page to bypass the browser's no-referrer policy, potentially leading to the disclosure of sensitive information. Rated as Medium severity with a CVSS score of 6.5, this vulnerability requires user interaction (UI:R) but has high confidentiality impact (C:H). There is no evidence of active exploitation, nor are there public exploit modules available in Metasploit or Nuclei, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 67.0.3396.62CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.