Description
readAsText() can indefinitely read the file picked by the user, rather than only once at the time the file is picked in File API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to access data on the user file system without explicit consent via a crafted HTML page.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4182-1 | chromium-browser security update |
EUVD |
EUVD-2018-17872 | readAsText() can indefinitely read the file picked by the user, rather than only once at the time the file is picked in File API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to access data on the user file system without explicit consent via a crafted HTML page. |
References
History
No history.
Status: PUBLISHED
Assigner: Chrome
Published:
Updated: 2024-08-05T05:54:52.701Z
Reserved: 2018-01-23T00:00:00.000Z
Link: CVE-2018-6109
No data.
Status : Modified
Published: 2019-01-09T19:29:08.353
Modified: 2024-11-21T04:10:05.173
Link: CVE-2018-6109
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD