AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-6109

MEDIUM · CVSS 6.5 EPSS 1.41%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-01-09 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2018-6109
Severity
MEDIUM
CVSS
6.5
EPSS
1.41%
Chrome

Original NVD Description

readAsText() can indefinitely read the file picked by the user, rather than only once at the time the file is picked in File API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to access data on the user file system without explicit consent via a crafted HTML page.