8.8
CVSSv3

CVE-2018-6055

Published: 25/09/2018 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Insufficient policy enforcement in Catalog Service in Google Chrome before 64.0.3282.119 allowed a remote malicious user to potentially run arbitrary code outside sandbox via a crafted HTML page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

Vendor Advisories

Synopsis Important: chromium-browser security update Type/Severity Security Advisory: Important Topic An update for chromium-browser is now available for Red Hat Enterprise Linux 6 SupplementaryRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability S ...
Insufficient policy enforcement in Catalog Service in Google Chrome prior to 6403282119 allowed a remote attacker to potentially run arbitrary code outside sandbox via a crafted HTML page ...

Github Repositories

A scraper (Mitre CVE database + GZD team's database) and short analysis on timing of vulnerability finding/fixing

GZD + Mitre This code (work in progress) scrapes the Mitre CVE database and compares it against the google zero day (GZD) team's database cvemitreorg/data/downloads/indexhtml bugschromiumorg/p/project-zero/issues/list?can=1&q=&sort=-id&colspec=ID%20Type%20Status%20Priority%20Milestone%20Owner%20Summary Intent GZD team's