Medium severity6.5NVD Advisory· Published Jan 9, 2019· Updated Jun 17, 2026
CVE-2018-6109
CVE-2018-6109
Description
readAsText() can indefinitely read the file picked by the user, rather than only once at the time the file is picked in File API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to access data on the user file system without explicit consent via a crafted HTML page.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
- osv-coords2 versionspkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2012%20SP2pkg:rpm/opensuse/chromium&distro=openSUSE%20Tumbleweed
< 66.0.3359.181-55.1+ 1 more
- (no CPE)range: < 66.0.3359.181-55.1
- (no CPE)range: < 93.0.4577.82-1.1
Patches
Vulnerability mechanics
References
6News mentions
0No linked articles in our index yet.