← back
CVE-2018-6176

CVE-2018-6176

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 0.5%
exploitation probability
0.5%top 61% of all CVEs
observed exploitation
nono source reports it
Insufficient file type enforcement in Extensions API in Google Chrome prior to 68.0.3440.75 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted Chrome Extension.
Affected products
Google · Chrome