CVE-2018-18358
MEDIUM5.7EPSS 0.11%Published: 12/11/2018Modified: 4/28/2026
Description
Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file.
Affected packages (1)
- Debian/chromiumfrom 0, < 71.0.3578.80-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.7 | CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |