A lack of host validation in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page, if the user is running a remote DevTools debugging server.
2018-12-04T17:29:01.540
2024-11-21T04:10:04.103
Modified
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:H/Au:N/C:P/I:P/A:P
4.9
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | redhat | linux_desktop | 6.0 | Yes |
| Operating System | redhat | linux_server | 6.0 | Yes |
| Operating System | redhat | linux_workstation | 6.0 | Yes |
| Operating System | debian | debian_linux | 8.0 | Yes |
| Operating System | debian | debian_linux | 9.0 | Yes |
| Application | chrome | < 66.0.3359.117 | Yes |