← Back to CVE List

CVE-2018-18351

Published: 2018-12-11T16:29Z
Last Modified: 2024-11-21T03:55Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass SameSite cookie policy via a crafted HTML page. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt