← back
CVE-2018-18349

CVE-2018-18349

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 1.0%
exploitation probability
1.0%top 40% of all CVEs
observed exploitation
nono source reports it
Remote frame navigations was incorrectly permitted to local resources in Blink in Google Chrome prior to 71.0.3578.80 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a crafted Chrome Extension.
Affected products
Google · Chrome