Insufficient data validation in crosh could lead to a command injection under chronos privileges in Networking in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to execute arbitrary code via a crafted HTML page.
2019-01-09T19:29:00.540
2024-11-21T03:14:38.613
Modified
CVSSv3.0: 7.3 (HIGH)
AV:L/AC:M/Au:N/C:P/I:P/A:P
3.4
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | chrome | < 61.0.3163.113 | Yes | |
| Operating System | chrome_os | * | No |