Vulnerability Description
A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the use of the JavaScript WebGL API.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chrome | - | |
| Mozilla | Firefox | - |
| Lg | Nexus 5 | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/104084Third Party AdvisoryVDB Entry
- https://www.kb.cert.org/vuls/id/283803Third Party AdvisoryUS Government Resource
- https://www.vusec.net/wp-content/uploads/2018/05/glitch.pdfTechnical DescriptionThird Party Advisory
- http://www.securityfocus.com/bid/104084Third Party AdvisoryVDB Entry
- https://www.kb.cert.org/vuls/id/283803Third Party AdvisoryUS Government Resource
- https://www.vusec.net/wp-content/uploads/2018/05/glitch.pdfTechnical DescriptionThird Party Advisory
FAQ
What is CVE-2018-10229?
CVE-2018-10229 is a vulnerability with a CVSS score of 4.8 (MEDIUM). A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the use of the JavaScript WebGL API.
How severe is CVE-2018-10229?
CVE-2018-10229 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-10229?
Check the references section above for vendor advisories and patch information. Affected products include: Google Chrome, Mozilla Firefox, Lg Nexus 5.