CVE-2018-6159 describes an insufficient policy enforcement vulnerability in Google Chrome versions prior to 68.0.3440.75, specifically within the ServiceWorker component. This flaw allows a remote attacker, via a crafted HTML page, to potentially extract sensitive information from the browser's process memory. With a CVSS score of 6.5 (MEDIUM), it requires user interaction (UI:R) but can be exploited over the network (AV:N) with low attack complexity (AC:L), leading to a high confidentiality impact (C:H). There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage beyond a single article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 68.0.3440.75CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.