CVE-2018-6149 describes a type confusion vulnerability in JavaScript within Google Chrome versions prior to 67.0.3396.87. This flaw allowed a remote attacker to achieve an out-of-bounds memory write by enticing a user to visit a specially crafted HTML page. With a CVSS score of 8.8 (HIGH), this vulnerability poses a significant risk, enabling high impact to confidentiality, integrity, and availability with low attack complexity. While there is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 67.0.3396.87CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.