7.2
CVSSv2

CVE-2018-6084

Published: 09/01/2019 Updated: 07/11/2023
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS before 66.0.3359.117 allowed a local malicious user to execute arbitrary code via an executable file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

debian debian linux 9.0

redhat enterprise linux desktop 6.0

redhat enterprise linux server 6.0

redhat enterprise linux workstation 6.0

Vendor Advisories

Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 6603359117 allowed a local attacker to execute arbitrary code via an executable file ...

Exploits

/* Google software updater ships with Chrome on MacOS and installs a root service (comgoogleKeystoneDaemonUpdateEngine) which lives here: /Library/Google/GoogleSoftwareUpdate/GoogleSoftwareUpdatebundle/Contents/MacOS/GoogleSoftwareUpdateDaemon This service vends a Distributed Object which exposes an API for updating google software running on ...