vendor:
Chrome
by:
Project Zero
7,5
CVSS
HIGH
Layout bug
20
CWE
Product Name: Chrome
Affected Version From: Chrome 67
Affected Version To: Chrome 68
Patch Exists: YES
Related CWE: N/A
CPE: a:google:chrome
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2018
Chrome bug 671328
A layout bug in Chrome allows an attacker to leak data from a select element by using the execCommand('selectAll') method. This can be used to bypass ASLR by using the unicode-range CSS descriptor.
Mitigation:
Disable JavaScript or use a browser that is not affected by this vulnerability.