CVE-2018-6177 is an information leak vulnerability in the media engine of Google Chrome versions prior to 68.0.3440.75. A remote attacker could exploit this by tricking a user into visiting a crafted HTML page, leading to the leakage of cross-origin data. This vulnerability has a CVSS score of 4.3 (Medium), indicating low impact on confidentiality and requiring user interaction. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered significant community discussion and media coverage, suggesting awareness despite its inactive Hot List status.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 68.0.3440.75CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.