Security Advisory

CVE-2018-18349

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-12-11 15:00:00
Last updated 2024-08-05 11:08:21
Assigner Chrome
CVSS score not scored
State PUBLISHED

Description

Remote frame navigations was incorrectly permitted to local resources in Blink in Google Chrome prior to 71.0.3578.80 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a crafted Chrome Extension.