CVE-2018-6179 describes an insufficient file access permission enforcement vulnerability within Google Chrome extensions prior to version 68.0.3440.75, also affecting Debian and Red Hat distributions. This medium-severity flaw (CVSS 6.5) allows an attacker to access local file system files if a user is tricked into installing a malicious extension. While no public exploit code or active exploitation is reported, the vulnerability has garnered some community discussion and media coverage, indicating a degree of awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 68.0.3440.75CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.