Google Chrome CVE-2018-6070 Cross Site Scripting Vulnerability

description-logoDescription

Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.

affected-products-logoAffected Applications

Google Chrome

CVE References

CVE-2018-6070