Описание
Insufficient target checks on the chrome.debugger API in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | released | 67.0.3396.99-0ubuntu0.17.10.1 |
| bionic | released | 67.0.3396.99-0ubuntu0.18.04.1 |
| cosmic | released | 67.0.3396.99-0ubuntu1 |
| devel | released | 67.0.3396.99-0ubuntu1 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was ignored [no longer updated]] |
| precise/esm | DNE | |
| trusty | ignored | end of standard support |
| trusty/esm | DNE | trusty was ignored [no longer updated] |
| upstream | released | 67.0.3396.62 |
| xenial | released | 67.0.3396.99-0ubuntu0.16.04.2 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | DNE | |
| cosmic | DNE | |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was ignored [Ubuntu touch end-of-life]] |
| esm-infra-legacy/xenial | ignored | Ubuntu touch end-of-life |
| esm-infra/xenial | ignored | end of ESM support, was ignored [Ubuntu touch end-of-life] |
| precise/esm | DNE | |
| trusty | ignored | end of standard support |
| trusty/esm | DNE | trusty was ignored [Ubuntu touch end-of-life] |
Показывать по
EPSS
6.8 Medium
CVSS2
8.8 High
CVSS3
Связанные уязвимости
Insufficient target checks on the chrome.debugger API in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.
Insufficient target checks on the chrome.debugger API in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.
Insufficient target checks on the chrome.debugger API in DevTools in G ...
Insufficient target checks on the chrome.debugger API in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.
Уязвимость в chrome.debugger API (DevTools) браузера Google Chrome, позволяющая нарушителю убедить пользователя установить вредоносное расширение и выполнить произвольный код
EPSS
6.8 Medium
CVSS2
8.8 High
CVSS3