CVE-2018-18358

critical
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
9.5

Description

Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2018-18358

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-201812-2

OS impact

OSVersionStatusFixed in
arch archfixed71.0.3578.80-1
debian debianbookwormfixed71.0.3578.80-1
debian debianbullseyefixed71.0.3578.80-1
debian debianforkyfixed71.0.3578.80-1
debian debiansidfixed71.0.3578.80-1
debian debiantrixiefixed71.0.3578.80-1

References

Verify integrity in audit chain (admin only). AS-IS.