Privilege Escalation via Crafted Chrome Extension in Google Chrome

Privilege Escalation via Crafted Chrome Extension in Google Chrome

CVE-2018-6176 · MEDIUM Severity

AV:L/AC:L/AU:N/C:P/I:P/A:P

Insufficient file type enforcement in Extensions API in Google Chrome prior to 68.0.3440.75 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted Chrome Extension.

Learn more about our Cis Benchmark Audit For Google Chrome.