CVE-2018-6140: Debian Linux

High severity, CVSS 8.8. EPSS: 2.6% chance of exploitation in the next 30 days.

Allowing the chrome.debugger API to attach to Web UI pages in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Google Chrome: before 67.0.3396.62 (fixed in 67.0.3396.62)
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only

Published 2019-01-09. Last modified 2026-06-17.