CVE-2018-6150 describes an incorrect handling of Cross-Origin Resource Sharing (CORS) within the ServiceWorker component of Google Chrome versions prior to 66.0.3359.117. This flaw allowed a remote attacker to leak sensitive cross-origin data through a specially crafted HTML page. Rated as MEDIUM severity with a CVSS score of 6.5, the vulnerability requires user interaction (UI:R) but has low attack complexity (AC:L) and could lead to high confidentiality impact (C:H). There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 66.0.3359.117CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.