CVE-2018-18358: Debian Linux

Medium severity, CVSS 5.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Google Chrome: before 71.0.3578.80 (fixed in 71.0.3578.80)
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only

Published 2018-12-11. Last modified 2026-06-17.