CVE-2018-6152

Publication date 4 December 2018

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

9.6 · Critical

Score breakdown

Description

The implementation of the Page.downloadBehavior backend unconditionally marked downloaded files as safe, regardless of file type in Google Chrome prior to 66.0.3359.117 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page and user interaction.

Status

Package Ubuntu Release Status
chromium-browser 18.10 cosmic
Fixed 68.0.3440.75-0ubuntu1
18.04 LTS bionic
Fixed 68.0.3440.75-0ubuntu0.18.04.1
16.04 LTS xenial
Fixed 68.0.3440.75-0ubuntu0.16.04.1
14.04 LTS trusty Not in release
oxide-qt 18.10 cosmic Not in release
18.04 LTS bionic Not in release
16.04 LTS xenial Ignored end of standard support
14.04 LTS trusty Not in release

Severity score breakdown

CVSS version: CVSS v3.0

Base score 9.6 · Critical

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H


Access our resources on patching vulnerabilities