SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-18358

Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file.

MEDIUM 5.7EPSS 0.44%

Does this matter?

Lower severity and a low EPSS score (0.44%). Track it; it rarely justifies an emergency change on its own.

Description

Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file.

CVSS 3.0
5.7 MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS
0.44% probability · 37th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
google/chrome · debian/debian linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation
Source
chrome-cve-admin@google.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.