CVE-2018-6171 describes a use-after-free vulnerability in Google Chrome's Bluetooth component, affecting versions prior to 68.0.3440.75. An attacker could exploit this by convincing a user to install a malicious Chrome Extension, leading to the potential disclosure of sensitive information from process memory. Rated Medium severity (CVSS 5.7), exploitation requires user interaction and network adjacency, but could result in high confidentiality impact. There is no evidence of active exploitation, and public exploit code is unavailable, with minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 68.0.3440.75CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.