CVE-2018-6083
Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in Google Chrome prior to 65.0.3325.146 all
Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to access privileged APIs via a crafted HTML page.
HIGH · CVSS 8.8
EPSS 0.00888
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules2
YARA rules0