Description
Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to trigger installation of an unwanted extension via a crafted HTML page.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4256-1 | chromium-browser security update |
EUVD |
EUVD-2018-17932 | Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to trigger installation of an unwanted extension via a crafted HTML page. |
References
History
No history.
Status: PUBLISHED
Assigner: Chrome
Published:
Updated: 2024-08-05T05:54:53.196Z
Reserved: 2018-01-23T00:00:00.000Z
Link: CVE-2018-6169
No data.
Status : Modified
Published: 2019-01-09T19:29:10.807
Modified: 2024-11-21T04:10:12.660
Link: CVE-2018-6169
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD