n0o.com - Personal archive of discovered vulns & writeups.

[CVE-2018-6110] Script Execution on non-HTML page in Google Chrome


Reported on : 24 Oct 2017 Shipped on : 25 Apr 2018 Type : Unexpected Results In Function : MIME Detection Parsing documents as HTML in Downloads in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to cause Chrome to execute scripts via a local non-HTML page.
https://crbug.com/777737