← Back to CVE List

CVE-2018-6152

Published: 2018-12-04T17:29Z
Last Modified: 2024-11-21T04:10Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The implementation of the Page.downloadBehavior backend unconditionally marked downloaded files as safe, regardless of file type in Google Chrome prior to 66.0.3359.117 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page and user interaction. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt