Learn about CVE-2018-6110, a vulnerability in Google Chrome before version 66.0.3359.117 that allowed remote attackers to execute scripts via non-HTML pages in the Downloads section. Find mitigation steps and prevention measures.
Google Chrome before version 66.0.3359.117 had a vulnerability that allowed a remote attacker to manipulate Chrome into running scripts by parsing non-HTML pages as HTML in the Downloads section.
Understanding CVE-2018-6110
This CVE involves an insufficient policy enforcement issue in Google Chrome.
What is CVE-2018-6110?
Before version 66.0.3359.117, Google Chrome had a vulnerability that enabled a remote attacker to manipulate Chrome into running scripts by parsing non-HTML pages as HTML in the Downloads section.
The Impact of CVE-2018-6110
The vulnerability allowed a remote attacker to execute scripts via a local non-HTML page in Google Chrome.
Technical Details of CVE-2018-6110
This section provides detailed technical information about the CVE.
Vulnerability Description
Parsing documents as HTML in Downloads in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to cause Chrome to execute scripts via a local non-HTML page.
Affected Systems and Versions
Exploitation Mechanism
The vulnerability could be exploited by a remote attacker manipulating Chrome into running scripts by parsing non-HTML pages as HTML in the Downloads section.
Mitigation and Prevention
Here are the steps to mitigate and prevent the CVE-2018-6110 vulnerability.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates
Ensure that all security patches and updates for Google Chrome are promptly applied.