Cross-Origin Resource Sharing (CORS) Vulnerability in Google Chrome prior to 65.0.3325.146

Cross-Origin Resource Sharing (CORS) Vulnerability in Google Chrome prior to 65.0.3325.146

CVE-2018-6066 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:N/A:N

Lack of CORS checking by ResourceFetcher/ResourceLoader in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

Learn more about our Cis Benchmark Audit For Google Chrome.