CVE-2018-6051
Status: ModifiedMedium (4.3)—
XSS Auditor in Google Chrome prior to 64.0.3282.119, did not ensure the reporting URL was in the same origin as the page it was on, which allowed a remote attacker to obtain referrer details via a crafted HTML page.
CVSS
- Version: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- Base score: 4.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.27%
- Percentile among all scored CVEs: 69
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (5)
CWEs
- CWE-79
References
- http://www.securityfocus.com/bid/102797
- http://www.securitytracker.com/id/1040282
- https://access.redhat.com/errata/RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/441275
- https://www.debian.org/security/2018/dsa-4103
- http://www.securityfocus.com/bid/102797
- http://www.securitytracker.com/id/1040282
- https://access.redhat.com/errata/RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/441275
- https://www.debian.org/security/2018/dsa-4103
Raw JSON (NVD)
Show
{
"id": "CVE-2018-6051",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "chrome-cve-admin@google.com",
"affectedData": [
{
"vendor": "Google",
"product": "Chrome",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "64.0.3282.119",
"versionType": "custom"
}
]
}
]
}
],
"published": "2018-09-25T14:29:03.523",
"references": [
{
"url": "http://www.securityfocus.com/bid/102797",
"source": "chrome-cve-admin@google.com"
},
{
"url": "http://www.securitytracker.com/id/1040282",
"source": "chrome-cve-admin@google.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2018:0265",
"source": "chrome-cve-admin@google.com"
},
{
"url": "https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html",
"source": "chrome-cve-admin@google.com"
},
{
"url": "https://crbug.com/441275",
"source": "chrome-cve-admin@google.com"
},
{
"url": "https://www.debian.org/security/2018/dsa-4103",
"source": "chrome-cve-admin@google.com"
},
{
"url": "http://www.securityfocus.com/bid/102797",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1040282",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://access.redhat.com/errata/RHSA-2018:0265",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://crbug.com/441275",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.debian.org/security/2018/dsa-4103",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "XSS Auditor in Google Chrome prior to 64.0.3282.119, did not ensure the reporting URL was in the same origin as the page it was on, which allowed a remote attacker to obtain referrer details via a crafted HTML page."
},
{
"lang": "es",
"value": "XSS Auditor en Google Chrome en versiones anteriores a la 64.0.3282.119 no aseguró que la URL de reporte estaba en el mismo origen que la página en la que estaba, lo que permitía que un atacante remoto obtuviese detalles de referrer mediante una página HTML manipulada."
}
],
"lastModified": "2026-06-17T02:01:14.720",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BA764B9B-8048-4775-A9F7-3DD41AA467A7",
"versionEndExcluding": "64.0.3282.119"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43"
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DEECE5FC-CACF-4496-A3E7-164736409252"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EE249E1B-A1FD-4E08-AA71-A0E1F10FFE97"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9BBCD86A-E6C7-4444-9D74-F861084090F0"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E5ED5807-55B7-47C5-97A6-03233F4FBC3A"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "chrome-cve-admin@google.com"
}